CISA Warns LiteSpeed cPanel Plugin Vulnerability Is Being Exploited in Attacks
ID: f87f29f7-4023-53bd-89ef-220533f2e235
STIX ID: report--f87f29f7-4023-53bd-89ef-220533f2e235
Feed Name: GBHackers
Threat Score
CISA has added CVE-2026-48172—a critical privilege escalation in the LiteSpeed cPanel plugin—to its KEV catalog, confirming active exploitation and mandating immediate remediation under BOD 22-01; the flaw allows any authenticated cPanel user to execute arbitrary scripts as root, placing shared hosting environments at high risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
