CISA Urges Immediate Patching of Exploited LiteSpeed cPanel Plugin Zero-Day
CISA on Tuesday urged federal agencies to immediately patch a critical-severity vulnerability in the LiteSpeed user-end plugin for cPanel that has been exploited in the wild.
Tracked as CVE-2026-48172 (CVSS score of 9.8), the flaw is described as a privilege escalation issue that could allow attackers to execute arbitrary scripts with root privileges.
LiteSpeed resolved the security defect last week in version 2.4.5 of the user-end plugin, noting that it had been exploited in the wild as a zero-day. LiteSpeed’s WHM plugin is not affected, it said.
“This vulnerability is being actively exploited, and poses a risk for all user-end plugin versions between v2.3 and v2.4.4,” LiteSpeed warned.
It also provided users with instructions on how to check if their servers have been affected, recommending immediate action if potential exploitation has been identified.
“We recommend you examine the IPs in the list, determine if they are valid, and if...
Copyright of this story solely belongs to securityweek.com. To see the full text click HERE