LiteSpeed cPanel Plugin 0-Day Exploited in the wild to Gain Server Root Access
ID: 48a3ed85-4e8f-5f71-a654-fa14dcb846e2
STIX ID: report--48a3ed85-4e8f-5f71-a654-fa14dcb846e2
Feed Name: cybersecurityNews.com
Threat Score
LiteSpeed disclosed and patched a critical 0‑day privilege escalation (CVE‑2026‑48172) in its cPanel user‑end plugin (affecting v2.3 through v2.4.4) that allows a cPanel user to execute arbitrary scripts as root; active exploitation has been confirmed, and operators are urged to apply cPanel plugin v2.4.5+ / WHM v5.3.1.0+ patches or uninstall the plugin, use provided log-search detection commands, and review for post‑compromise activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
