CVE-2026-48172
Sfruttamento noto · CISA KEV
EPSS 1% (62º percentile).
Data di correzione federale CISA 29 mag
Vulnerabilità · 126 giorni fa
L'assunzione errata è che le autorizzazioni di un utente cPanel contengano il danno. Nel plugin cPanel lato utente di LiteSpeed, qualsiasi account tenant può abusare di lsws.redisAble per eseguire script come root, quindi un account di hosting compromesso può trasformarsi in una compromissione completa del server.
Sfruttamento noto · CISA KEV
EPSS 1% (62º percentile).
Data di correzione federale CISA 29 mag
3 fonti che coprono questa storia
CISA gives feds 4 days to patch actively exploited cPanel plugin flaw
federal agencies four days to secure their servers against a critical vulnerability in the LiteSpeed cPanel user-end plugin, which is actively being exploited in attacks.
CISA Urges Immediate Patching of Exploited LiteSpeed cPanel Plugin Zero-Day
Resolved last week, the vulnerability was exploited in the wild as a zero-day to execute scripts with root privileges.
LiteSpeed cPanel Plugin CVE-2026-48172 Exploited to Run Scripts as Root
CVE-2026-48172 lets cPanel users run scripts as root, affecting LiteSpeed plugin 2.3–2.4.4 and exposing servers.
Part of the PlainSec briefing for 2026-05-24