cPanel security advisory (AV26-861)
Serial Number: AV26-861 Date: August 28, 2026 As of August 27, 2026, cPanel is affected by vulnerabilities in the following products: cPanel & WebHost Manager (WHM) software Prior to 11.110.0.141 Prior to 11.134.0.53 Prior to 11.136.0.37 Prior to 11.138.0.2 Prior to WP2: 11.138.1.7 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available Security: CVE-2026-65643 Vulnerability in cPanel’s Domain Parking Functionality - August 27, 2026 cPanel Security
CSIRTS triage
- What
- Vulnerability in cPanel's Domain Parking functionality (CVE-2026-65643).
- Who is affected
- cPanel & WebHost Manager installations running versions prior to the specified patched versions.
- Urgency
- Medium; specific attack details are not provided but cPanel marks as requiring attention.
- Action
- Update to cPanel versions 11.110.0.141, 11.134.0.53, 11.136.0.37, 11.138.0.2, or 11.138.1.7 or later as applicable to your branch.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch cPanel & WebHost Manager
Get an email when a new cPanel & WebHost Manager advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/cpanel-security-advisory-av26-861
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-656430.90% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 58% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-65643 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
More from Canadian Centre for Cyber Security
- unknownMikrotik security advisory (AV26-887) – Update 12026-09-11
- criticalAL26-020 - Vulnerabilities Impacting MikroTik RouterOS - CVE-2026-67276, CVE-2026-67277 and CVE-2026-860602026-09-10
- unknownHPE security advisory (AV26-909)2026-09-10
- unknownWebPros security advisory (AV26-908)2026-09-10
- unknownAdobe security advisory (AV26-808) – Update 12026-09-10