CISA gives feds 4 days to patch actively exploited cPanel plugin flaw
ID: 90035ec0-5db4-5ff6-bc6f-a9532d142fc9
STIX ID: report--90035ec0-5db4-5ff6-bc6f-a9532d142fc9
Feed Name: Bleeping Computer
Threat Score
A critical privilege-escalation flaw (CVE-2026-48172) in the LiteSpeed cPanel user plugin allows unauthenticated attackers to execute arbitrary scripts as root; the bug (lsws.redisAble incorrect privilege handling) is being actively exploited, LiteSpeed released urgent updates, and CISA ordered U.S. federal agencies to patch immediately while providing detection and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
