< Back to all clusters
[TECHNOLOGY] · United States, Netherlands · 3 sources

Critical LiteSpeed cPanel Plugin Flaw (CVE‑2026‑48172) Exploited, Prompting Urgent Patches

cPanel warned users that a critical flaw in the LiteSpeed cPanel plug‑in (CVE‑2026‑48172) is being actively exploited. The vulnerability lets any authenticated cPanel user run arbitrary scripts with root privileges, potentially compromising the entire server and exposing data from other tenants in shared‑hosting environments.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the bug to its Known Exploited Vulnerabilities catalog and issued a three‑day directive for federal agencies to apply the fix by May 29, 2026. cPanel released an update that automatically removes the vulnerable plug‑in, and LiteSpeed published version 2.4.7 addressing additional attack vectors. Administrators are urged to verify removal, install the patch, and consider stricter permission controls until the issue is fully mitigated.