<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>CPanel &amp; WebHost Manager (&lt; 11.138.0.2) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/cpanel--webhost-manager--11.138.0.2/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 29 Aug 2026 03:13:20 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/cpanel--webhost-manager--11.138.0.2/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>CVE-2026-65643 Vulnerability in cPanel Domain Parking</title><link>https://feed.craftedsignal.io/briefs/2026-08-cpanel-vulnerability/</link><pubDate>Sat, 29 Aug 2026 03:13:20 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-cpanel-vulnerability/</guid><description>A vulnerability in cPanel &amp; WebHost Manager (WHM) Domain Parking functionality identified as CVE-2026-65643 requires urgent patching to prevent potential system compromise.</description><content:encoded><![CDATA[<p>On August 27, 2026, cPanel disclosed a security vulnerability, CVE-2026-65643, affecting the Domain Parking functionality within its cPanel &amp; WebHost Manager (WHM) software. This flaw poses a risk to administrators managing web hosting environments, as unauthenticated or local attackers could potentially leverage the vulnerability to impact the confidentiality, integrity, or availability of the underlying server. Impacted versions include all releases prior to 11.110.0.141, 11.134.0.53, 11.136.0.37, 11.138.0.2, and 11.138.1.7 (WP2). Organizations utilizing affected versions should immediately evaluate their exposure and apply the vendor-provided security patches to mitigate potential unauthorized access or service disruption.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-65643 may allow an attacker to bypass intended security controls within the Domain Parking feature. While specific exploit primitives remain restricted, this could lead to unauthorized resource modification or information disclosure. The vulnerability affects a broad range of cPanel &amp; WHM deployments, making it a critical priority for managed service providers and hosting administrators to secure their infrastructure.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for administrators and security teams:</p>
<ul>
<li>Upgrade all instances of cPanel &amp; WebHost Manager to the patched versions: 11.110.0.141, 11.134.0.53, 11.136.0.37, 11.138.0.2, or 11.138.1.7 (WP2) as specified in the cPanel security advisory.</li>
<li>Review the cPanel support portal for specific release notes regarding CVE-2026-65643 to identify any additional configuration changes required beyond the patch.</li>
<li>Audit current Domain Parking configurations on public-facing servers for any unusual activity or modifications recorded since the release of the advisory.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>