Under certain conditions, attackers can target the widely used web hosting control panel software cPanel/WHM and execute malicious code with root privileges. Fixed versions are already available for download, and you should install them promptly.
Prerequisite: already authenticated access
According to a vendor advisory, an attacker must already be authenticated and have access to the parked or addon domains management function. If that's the case, they can push their own files onto a server through an unspecified method. That results in malicious code executing with root privileges, giving attackers full control over the affected system. So far, the developers have no indication that attackers are already exploiting the vulnerability (CVE-2026-65643). A CVSS score rating is still pending, but given the far-reaching consequences of a successful attack, a critical rating seems likely.
These versions close the gap
All currently supported versions of the software are affected. Make sure at least one of the following fixed releases is installed: 11.110.0.14, 11.134.0.53, 11.136.0.37, 11.138.0.2, or WP2: 11.138.1.7.
How to identify systems that have already been successfully attacked isn't known yet. Even though there are no documented attacks so far, you shouldn't wait too long to update. As widely used software, cPanel/WHM is a worthwhile target for attackers, root attacks on cPanel instances with the LiteSpeed plugin made headlines just this past June.