logo

CISA Warns of LiteSpeed cPanel Plugin Vulnerability Exploited in Attacks

ID: e25abe6d-3af8-5866-92ad-03dd3018ca4c

STIX ID: report--e25abe6d-3af8-5866-92ad-03dd3018ca4c

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-05-27

Date Updated: 2026-05-27

Author: Abinaya

...
...

CISA has issued an urgent warning for CVE-2026-48172, a critical privilege-escalation vulnerability in the LiteSpeed cPanel plugin that is being actively exploited; authenticated cPanel users can gain root-level script execution. The flaw was added to CISA’s KEV catalog with a remediation deadline, and organizations are advised to apply patches, restrict permissions, enhance monitoring, or disable the plugin to mitigate the high risk to multi-tenant hosting and cloud environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.