CVE-2026-65643: cPanel
High severity, CVSS 8.8. EPSS: 0.9% chance of exploitation in the next 30 days.
Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root.
Affected products
- cPanel cPanel: before 110.0.141 (fixed in 110.0.141); from 112.0.0, before 134.0.53 (fixed in 134.0.53); from 136.0.0, before 136.0.37 (fixed in 136.0.37); from 138.0.0, before 138.0.2 (fixed in 138.0.2); from 138.1.0, before 138.1.7 (fixed in 138.1.7)
Published 2026-09-01. Last modified 2026-09-17.