cPanel warned that an undisclosed critical privilege-escalation flaw in LiteSpeed Web Server Enterprise before version 6.3.7 could allow a low-privilege shared-hosting account to bypass tenant-isolation controls, including CloudLinux CageFS, and obtain root access to the host. Successful exploitation could expose other customers’ websites, server configuration, and the underlying shared server.
LiteSpeed released version 6.3.7, and cPanel urged administrators to install it manually because automatic-update availability may be delayed. No CVE, severity score, technical root cause, workaround, indicators of compromise, or confirmed exploitation status has been published; the advisory applies to the Enterprise edition, while exposure of OpenLiteSpeed and 6.4.0 release candidates remains unconfirmed.

Get the actors, campaigns, and ATT&CK mapping behind it.
6 events from the most recent confirmed update back to the earliest known activity.
cPanel issued a security notice warning that LiteSpeed Web Server Enterprise versions before 6.3.7 contain a critical flaw that could let a low-privileged shared-hosting user bypass isolation controls, including CloudLinux CageFS, and obtain root access. It urged administrators to manually install version 6.3.7 because automatic-update availability could be delayed.
LiteSpeed released Web Server Enterprise version 6.3.7, which cPanel identified as the remediation version for a critical privilege-escalation issue affecting earlier Enterprise versions.
LiteSpeed made a 6.4.0 RC1 prerelease available. The later cPanel notice did not establish whether 6.4.0 release candidates were affected by the Enterprise privilege-escalation flaw.
LiteSpeed disclosed a second actively exploited root-access vulnerability in its cPanel end-user plugin, among CVE-2026-48172 and CVE-2026-54420. The company patched the vulnerability in the plugin.
LiteSpeed disclosed one of two actively exploited root-access vulnerabilities affecting its cPanel end-user plugin, later identified collectively with CVE-2026-48172 and CVE-2026-54420. LiteSpeed patched the issue in the plugin.
CISA subsequently added CVE-2026-48172 and CVE-2026-54420, the actively exploited LiteSpeed cPanel end-user plugin vulnerabilities, to its Known Exploited Vulnerabilities catalog.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
mkd-cirt.mk
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.