Close Menu
Tech Nova Mindset – Empower Innovation and Forward Thinking

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    AI models need more data about biology, and OpenAI is paying to create it

    September 16, 2026

    Single CAR T Injection Eases Multiple Sclerosis Symptoms in Small Trial

    September 15, 2026

    AI ‘Actor’ Tilly Norwood Told Me That ‘All Lives Matter’

    September 15, 2026
    Facebook X (Twitter) Instagram
    Trending
    • AI models need more data about biology, and OpenAI is paying to create it
    • Single CAR T Injection Eases Multiple Sclerosis Symptoms in Small Trial
    • AI ‘Actor’ Tilly Norwood Told Me That ‘All Lives Matter’
    • Roundtables: Could AI really kill us all?
    • How Elon Musk and Tesla Forged a New EV Path
    • The Download: AI doomers, whistleblowing agents, and de-aged livers
    • Inside the Inference Hardware Revolution Of 2026
    • What must happen for AI’s trillion-dollar gamble to pay off
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    • Home
    • Gadgets
    • Reviews
    • Tech News
    • Future Tech
    • AI & Robotics
    • How-To Guides
    • More
      • Cybersecurity
      • Startups & Innovation
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    Home»Cybersecurity»CISA Urges Immediate Patching of Exploited LiteSpeed cPanel Plugin Zero-Day
    Cybersecurity

    CISA Urges Immediate Patching of Exploited LiteSpeed cPanel Plugin Zero-Day

    kirklandc008@gmail.comBy kirklandc008@gmail.comMay 27, 2026No Comments2 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    CISA KEV
    Share
    Facebook Twitter LinkedIn Pinterest Email

    CISA on Tuesday urged federal agencies to immediately patch a critical-severity vulnerability in the LiteSpeed user-end plugin for cPanel that has been exploited in the wild.

    Tracked as CVE-2026-48172 (CVSS score of 9.8), the flaw is described as a privilege escalation issue that could allow attackers to execute arbitrary scripts with root privileges.

    LiteSpeed resolved the security defect last week in version 2.4.5 of the user-end plugin, noting that it had been exploited in the wild as a zero-day. LiteSpeed’s WHM plugin is not affected, it said.

    “This vulnerability is being actively exploited, and poses a risk for all user-end plugin versions between v2.3 and v2.4.4,” LiteSpeed warned.

    It also provided users with instructions on how to check if their servers have been affected, recommending immediate action if potential exploitation has been identified.

    “We recommend you examine the IPs in the list, determine if they are valid, and if not, block them. To determine any damage done, examine the system logs for any actions taken by the detected IPs,” LiteSpeed said.

    Advertisement. Scroll to continue reading.

    Users should upgrade to LiteSpeed WHM Plugin version 5.3.1.0 (bundled with the user-end plugin version 2.4.7) or higher, which contain patches for the vulnerability. If patching is not possible, users are advised to completely remove the plugin.

    On May 19, cPanel pushed a nightly update that removed the LiteSpeed user-end plugin for all cPanel versions, underlining that the exploited CVE allowed unauthorized root access to the server.

    On Tuesday, CISA added CVE-2026-48172 to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to patch it or remove the vulnerable plugin versions by May 29, in line with Binding Operational Directive (BOD) 22-01 guidance.

    Related: Hackers Exploited KnowledgeDeliver Zero-Day for Web Shell Deployment

    Related: Ghost CMS Vulnerability Exploited to Hack Over 700 Websites

    Related: Verizon DBIR 2026: Vulnerability Exploitation Overtakes Credential Theft as Top Breach Vector

    Related: Over 40,000 Servers Compromised in Ongoing cPanel Exploitation

    CISA cPanel exploited LiteSpeed Patching plugin urges zeroday
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    kirklandc008@gmail.com
    • Website

    Related Posts

    Chrome Needs Twice-a-Week Patching Thanks to AI Bug Hunting

    July 31, 2026

    Ransomware in 2026: More groups, more victims, no slowdown

    July 26, 2026

    The 3 types of people who will excel in the AI agent era, according to tech leaders

    July 26, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Nothing CEO says phone prices are going to keep going up

    June 12, 20267 Views

    The best VPN routers of 2026: Expert tested and reviewed

    June 14, 20263 Views

    Google DeepMind Plans to Track AGI Progress With These 10 Traits of General Intelligence

    March 21, 20263 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Recent Posts
    • AI models need more data about biology, and OpenAI is paying to create it
    • Single CAR T Injection Eases Multiple Sclerosis Symptoms in Small Trial
    • AI ‘Actor’ Tilly Norwood Told Me That ‘All Lives Matter’
    • Roundtables: Could AI really kill us all?
    • How Elon Musk and Tesla Forged a New EV Path

    AI models need more data about biology, and OpenAI is paying to create it

    September 16, 2026

    Single CAR T Injection Eases Multiple Sclerosis Symptoms in Small Trial

    September 15, 2026

    AI ‘Actor’ Tilly Norwood Told Me That ‘All Lives Matter’

    September 15, 2026

    Roundtables: Could AI really kill us all?

    September 15, 2026
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 TechNovaMindset. Designed by By Pro.

    Type above and press Enter to search. Press Esc to cancel.