CVSS 10.0 Zero-Day: Active Attacks Exploit LiteSpeed cPanel Plugin for Root Server Access
ID: 13e9d020-b644-5dbd-9403-2d9a2ef6b9b2
STIX ID: report--13e9d020-b644-5dbd-9403-2d9a2ef6b9b2
Feed Name: securityonline.info
Threat Score
A critical, actively exploited vulnerability (CVE-2026-48172, CVSS 10.0) in the LiteSpeed cPanel plugin allows remote privilege escalation to root. Administrators should scan cPanel logs using the provided grep command and urgently upgrade to plugin v2.4.7 (WHM Plugin v5.3.1.0), which includes the fix and multiple security hardening changes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
