U.S. CISA adds LiteSpeed cPanel Plugin flaw to its Known Exploited Vulnerabilities catalog
ID: 3aafeffe-18ec-5e71-b32a-918000190a9e
STIX ID: report--3aafeffe-18ec-5e71-b32a-918000190a9e
Feed Name: Security Affairs
Threat Score
CISA added CVE-2026-48172 — a critical (CVSS 10.0) privilege-escalation flaw in the LiteSpeed cPanel user-end plugin (versions v2.3–v2.4.4) — to its Known Exploited Vulnerabilities catalog after active exploitation was observed; administrators are urged to apply emergency patches (upgrade to ≥v2.4.7), search cPanel logs for suspicious redis-related API calls using the provided grep command, review IP activity, and remediate by the CISA deadline.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
