Three flaws that let one hosting account take over a server, and when we closed each one
Between 27 August and 14 September, three flaws were published in cPanel and LiteSpeed that let a single account on a shared server take control of the whole machine. All three are fixed on our servers, and there is nothing for you to install or change. Here is when each fix went in.
Your website shares its server with other hosting accounts. The server's own software keeps them apart: each account sees its own files, runs as its own user, and cannot touch the server's own files and settings. You don't choose who else is on a shared server, so that separation is a large part of what you are trusting us with.
Between 27 August and 14 September, three flaws were published that break it. Each one lets someone with an ordinary account on the server run commands as root, the administrator of the whole machine, and root can read or change every site on it.
The three flaws#
- cPanel Domain Parking, CVE-2026-65643 (27 August). An account allowed to add parked or addon domains could create files of its choosing on the server, which leads to code running as root.
- cPanel EmailTrack, CVE-2026-67401 (8 September). A SQL injection in cPanel's email delivery tracking let an account with access to email do the same.
- LiteSpeed Web Server Enterprise before 6.3.7 (14 September, published without a CVE number). A low-privileged website user could gain root, and the flaw can get past CageFS, the CloudLinux layer that walls each account off from the others.
When they were closed on our servers#
cPanel on our servers checks for urgent security releases every hour and installs them without waiting for anyone. It found the Domain Parking fix on 27 August and had it installed at 16:00 UTC. The EmailTrack fix went in on 8 September at 16:16 UTC. Both were in place the same day cPanel published its advisory.
LiteSpeed released the fixed version, 6.3.7, on 11 September, three days before the advisory. We installed it at 11:31 UTC on 13 September, the day before cPanel published the advisory. A further build with one more security fix followed on 15 September, and our servers have run it since 06:53 UTC on 16 September.
Two kernel flaws from August#
Two Linux kernel flaws of the same kind were disclosed in early August, CVE-2026-64564 and CVE-2026-72389. CloudLinux, the operating system on our servers, says neither can be used from an ordinary account on CloudLinux 9 as it ships, and on ours the kernel module the first one needs is not installed. Both are patched in the running kernel anyway, without a reboot.
What you need to do#
Nothing to install or change. The flaws were in the software that runs the server, not in anything inside your account, so the fixes happened entirely on our side.
If you have noticed something odd on your site, or want to know how a flaw like this is handled on your account, ask us.