0x

guest@0xbase ~$ read-only mode. Posting requires EU location.

LiteSpeed cPanel Plugin: Critical Vulnerability Under Active Attack (heise.de)

· 63d ago · Report · Spotlight this ·
0xBASE INTEL BRIEF
  • Critical privilege escalation in LiteSpeed cPanel plugin (CVE-2026-48172, CVSS 9.8)
  • Allows root-level code execution; active attacks confirmed by CISA and LiteSpeed
  • Patch immediately to version 2.4.5; use grep to detect exploitation

"A critical vulnerability (CVE-2026-48172, CVSS 9.8) in the LiteSpeed plugin for cPanel allows any cPanel user to execute arbitrary code as root. CISA has added it to its Known Exploited Vulnerabilities catalog. LiteSpeed released an update (version 2.4.5 or later) to fix the flaw. Administrators can use a grep command to check for compromise."

#cPanel vulnerability #LiteSpeed plugin #CVE-2026-48172

Discussion Matrix

0 segments

no comments yet.