LiteSpeed cPanel Plugin 0-Day Exploited for Server Root Access
ID: 020af072-c9ed-5ce7-a378-7363010a724d
STIX ID: report--020af072-c9ed-5ce7-a378-7363010a724d
Feed Name: GBHackers
Threat Score
A critical zero-day (CVE-2026-48172) in the LiteSpeed cPanel User-End plugin enables any authenticated cPanel user to execute arbitrary commands as root and is being actively exploited; administrators should immediately run the provided IOC grep, rotate credentials if exploitation is detected, and either upgrade to the patched LiteSpeed WHM Plugin v5.3.1.0 (bundled with cPanel Plugin v2.4.7) or uninstall the vulnerable plugin.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
