news.mlab.sh
Back to the feed
vulnerability

CISA Urges Immediate Patching of Exploited LiteSpeed cPanel Plugin Zero-Day

Critical
Summary

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical alert urging immediate patching of a zero-day vulnerability (CVE-2026-48172) in the LiteSpeed cPanel plugin. This flaw allows for privilege escalation and has been actively exploited by attackers, posing a significant risk to systems running the vulnerable plugin versions. CISA’s directive mandates patching or removal of the plugin by May 29th to mitigate the ongoing compromise of numerous servers.

The vulnerability, assigned a CVSS score of 9.8, centers around a privilege escalation issue within the LiteSpeed user-end plugin for cPanel. Attackers have been actively exploiting this zero-day, targeting systems running versions between 2.3 and 2.4.4. LiteSpeed initially addressed the issue in version 2.4.5 but confirmed exploitation was already occurring. The CISA’s action, formalized through a Binding Operational Directive (BOD), highlights the urgency of the situation, particularly for federal agencies and any organization utilizing cPanel.

Read the full article at SecurityWeek