{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/cpanel--webhost-manager--11.134.0.53/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["cPanel \u0026 WebHost Manager (\u003c 11.110.0.141)","cPanel \u0026 WebHost Manager (\u003c 11.134.0.53)","cPanel \u0026 WebHost Manager (\u003c 11.136.0.37)","cPanel \u0026 WebHost Manager (\u003c 11.138.0.2)","cPanel \u0026 WebHost Manager (\u003c 11.138.1.7 (WP2))"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["cPanel"],"content_html":"\u003cp\u003eOn August 27, 2026, cPanel disclosed a security vulnerability, CVE-2026-65643, affecting the Domain Parking functionality within its cPanel \u0026amp; WebHost Manager (WHM) software. This flaw poses a risk to administrators managing web hosting environments, as unauthenticated or local attackers could potentially leverage the vulnerability to impact the confidentiality, integrity, or availability of the underlying server. Impacted versions include all releases prior to 11.110.0.141, 11.134.0.53, 11.136.0.37, 11.138.0.2, and 11.138.1.7 (WP2). Organizations utilizing affected versions should immediately evaluate their exposure and apply the vendor-provided security patches to mitigate potential unauthorized access or service disruption.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-65643 may allow an attacker to bypass intended security controls within the Domain Parking feature. While specific exploit primitives remain restricted, this could lead to unauthorized resource modification or information disclosure. The vulnerability affects a broad range of cPanel \u0026amp; WHM deployments, making it a critical priority for managed service providers and hosting administrators to secure their infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for administrators and security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all instances of cPanel \u0026amp; WebHost Manager to the patched versions: 11.110.0.141, 11.134.0.53, 11.136.0.37, 11.138.0.2, or 11.138.1.7 (WP2) as specified in the cPanel security advisory.\u003c/li\u003e\n\u003cli\u003eReview the cPanel support portal for specific release notes regarding CVE-2026-65643 to identify any additional configuration changes required beyond the patch.\u003c/li\u003e\n\u003cli\u003eAudit current Domain Parking configurations on public-facing servers for any unusual activity or modifications recorded since the release of the advisory.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-29T03:13:20Z","date_published":"2026-08-29T03:13:20Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cpanel-vulnerability/","summary":"A vulnerability in cPanel \u0026 WebHost Manager (WHM) Domain Parking functionality identified as CVE-2026-65643 requires urgent patching to prevent potential system compromise.","title":"CVE-2026-65643 Vulnerability in cPanel Domain Parking","url":"https://feed.craftedsignal.io/briefs/2026-08-cpanel-vulnerability/"}],"language":"en","title":"CraftedSignal Threat Feed - CPanel \u0026 WebHost Manager (\u003c 11.134.0.53)","version":"https://jsonfeed.org/version/1.1"}