Another cPanel Vulnerability — Already Patched, WHP Migrations Still Free

  • Thursday, 27th August, 2026
  • 09:14am

When we first opened up free migrations to WHP, we pointed to a rough three-week stretch where cPanel issued three Technical Security Releases covering nine-plus CVEs — including a CVSS 9.8 pre-auth bypass that had been exploited in the wild for two months before a patch existed. cPanel told customers to expect that cadence to continue.

They were right. On August 27, 2026, cPanel disclosed CVE-2026-65643, a vulnerability in the domain parking feature. Any authenticated cPanel account holder able to add a parked or addon domain — a completely ordinary, low-privilege action — could create arbitrary files on the server, leading to code execution as root. That's full control of the server, and every account, site, and database on it, triggered by something as routine as parking a domain.

We patched all affected servers as soon as cPanel released the fix. No customer data was affected, and there's nothing you need to do.

If you haven't made the move yet, our offer still stands: free migrations from cPanel to WHP, our own containerized hosting platform. We handle your files, databases, DNS, email, SSL, and cron jobs at no cost — you approve the cutover. Email support@anhonesthost.com to schedule a window, or read more about WHP here: https://kb.anhonesthost.com/whp/getting-started/welcome/

 

— The AnHonestHost Team

« Back