Threat Intelligence Brief
Curated summary with source attribution
Source: thehackernews.com
Threat Risk: High
Victim: Shared hosting providers and cPanel administrators
Incident: A critical privilege escalation vulnerability in cPanel/WHM allows root-level code execution.
Impact: Complete server takeover and compromise of all hosted accounts on the machine.
Attacker: Authenticated cPanel account holders
Analysis: CVE-2026-65643 allows authenticated users with the ability to manage parked or addon domains to create arbitrary files on the server. This capability leads to remote code execution with root privileges, effectively breaking multi-tenant isolation. While not yet confirmed as exploited in the wild, the potential for total server compromise is severe.
Recommendations: Update cPanel & WHM to the latest patched versions immediately.; Manually trigger updates via /scripts/upcp –force if automatic updates are disabled.; Audit system directories for unexpected files created by hosting accounts.
Source: The Hacker News
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source