CVE-2026-48172
Known exploited · CISA KEV
EPSS 19% (97th percentile), up from 1%.
CISA federal remediation date May 29
Vulnerabilities & Exploits · Zero-Day Exploit
The broken assumption is that a cPanel user’s permissions contain the damage. In LiteSpeed’s user-end cPanel plugin, any tenant account can abuse lsws.redisAble to run scripts as root, so one compromised hosting account can turn into full server compromise.
LiteSpeed says CVE-2026-48172 is being actively exploited and fixed it in plugin 2.4.5. The affected range is 2.3 through 2.4.4, and LiteSpeed published a log grep indicator, cpanel_jsonapi_func=redisAble, to help operators find exposed hosts.
For shared hosting providers, account-level containment is the wrong model if this marker appears. The question shifts from one bad cPanel user to whether the host itself is already trusted compromised.
3 sources · May 27
Known exploited · CISA KEV
EPSS 19% (97th percentile), up from 1%.
CISA federal remediation date May 29
BleepingComputer
CISA gives feds 4 days to patch actively exploited cPanel plugin flaw
federal agencies four days to secure their servers against a critical vulnerability in the LiteSpeed cPanel user-end plugin, which is actively being exploited in attacks.
originalSecurityWeek
CISA Urges Immediate Patching of Exploited LiteSpeed cPanel Plugin Zero-Day
Resolved last week, the vulnerability was exploited in the wild as a zero-day to execute scripts with root privileges.
originalThe Hacker News
LiteSpeed cPanel Plugin CVE-2026-48172 Exploited to Run Scripts as Root
CVE-2026-48172 lets cPanel users run scripts as root, affecting LiteSpeed plugin 2.3–2.4.4 and exposing servers.
originalPart of the PlainSec briefing for 2026-05-24
Every edition of this story: Shared cPanel Hosts Face Root Compromise Risk