CISA Urges Immediate Patching of Exploited LiteSpeed cPanel Plugin Zero-Day
A critical zero-day vulnerability (CVE-2026-48172) in the LiteSpeed user-end plugin for cPanel was exploited in the wild to execute arbitrary scripts with root privileges. The vulnerability affects versions 2. 3 through 2. 4. 4 of the plugin and was resolved in version 2. 4. 5. LiteSpeed’s WHM plugin is not affected. The vulnerability allows privilege escalation leading to unauthorized root access. CISA has added this vulnerability to its Known Exploited Vulnerabilities catalog and urges immediate patching or removal of the vulnerable plugin.
AI Analysis
Technical Summary
CVE-2026-48172 is a critical privilege escalation vulnerability in the LiteSpeed user-end plugin for cPanel, allowing attackers to execute arbitrary scripts with root privileges. The flaw was actively exploited as a zero-day before being patched in version 2.4.5 of the user-end plugin. The vulnerability affects all user-end plugin versions from 2.3 to 2.4.4. LiteSpeed’s WHM plugin is unaffected. cPanel responded by removing the vulnerable plugin from all cPanel versions via a nightly update. CISA has included this vulnerability in its Known Exploited Vulnerabilities catalog and mandated patching or removal by May 29, 2026, under Binding Operational Directive 22-01. The vendor recommends upgrading to WHM Plugin version 5.3.1.0 or higher, which bundles the patched user-end plugin version 2.4.7. If patching is not feasible, complete removal of the plugin is advised.
Potential Impact
The vulnerability allows attackers to escalate privileges to root level on affected servers, enabling execution of arbitrary scripts with full administrative control. This poses a severe risk of unauthorized access and potential full compromise of affected systems. The vulnerability was actively exploited in the wild as a zero-day before the patch was released. The impact is critical due to the level of access gained and the active exploitation status prior to remediation.
Mitigation Recommendations
A patch is available in LiteSpeed user-end plugin version 2.4.5 and WHM Plugin version 5.3.1.0 or higher (which bundles user-end plugin 2.4.7). Users should immediately upgrade to these versions to remediate the vulnerability. If patching is not possible, the vendor and cPanel recommend complete removal of the LiteSpeed user-end plugin. cPanel has also removed the vulnerable plugin from all cPanel versions via a nightly update. CISA mandates patching or removal by May 29, 2026, under BOD 22-01. Users should also review system logs and block any suspicious IPs identified during investigation as per vendor guidance.
CISA Urges Immediate Patching of Exploited LiteSpeed cPanel Plugin Zero-Day
Description
A critical zero-day vulnerability (CVE-2026-48172) in the LiteSpeed user-end plugin for cPanel was exploited in the wild to execute arbitrary scripts with root privileges. The vulnerability affects versions 2. 3 through 2. 4. 4 of the plugin and was resolved in version 2. 4. 5. LiteSpeed’s WHM plugin is not affected. The vulnerability allows privilege escalation leading to unauthorized root access. CISA has added this vulnerability to its Known Exploited Vulnerabilities catalog and urges immediate patching or removal of the vulnerable plugin.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-48172 is a critical privilege escalation vulnerability in the LiteSpeed user-end plugin for cPanel, allowing attackers to execute arbitrary scripts with root privileges. The flaw was actively exploited as a zero-day before being patched in version 2.4.5 of the user-end plugin. The vulnerability affects all user-end plugin versions from 2.3 to 2.4.4. LiteSpeed’s WHM plugin is unaffected. cPanel responded by removing the vulnerable plugin from all cPanel versions via a nightly update. CISA has included this vulnerability in its Known Exploited Vulnerabilities catalog and mandated patching or removal by May 29, 2026, under Binding Operational Directive 22-01. The vendor recommends upgrading to WHM Plugin version 5.3.1.0 or higher, which bundles the patched user-end plugin version 2.4.7. If patching is not feasible, complete removal of the plugin is advised.
Potential Impact
The vulnerability allows attackers to escalate privileges to root level on affected servers, enabling execution of arbitrary scripts with full administrative control. This poses a severe risk of unauthorized access and potential full compromise of affected systems. The vulnerability was actively exploited in the wild as a zero-day before the patch was released. The impact is critical due to the level of access gained and the active exploitation status prior to remediation.
Mitigation Recommendations
A patch is available in LiteSpeed user-end plugin version 2.4.5 and WHM Plugin version 5.3.1.0 or higher (which bundles user-end plugin 2.4.7). Users should immediately upgrade to these versions to remediate the vulnerability. If patching is not possible, the vendor and cPanel recommend complete removal of the LiteSpeed user-end plugin. cPanel has also removed the vulnerable plugin from all cPanel versions via a nightly update. CISA mandates patching or removal by May 29, 2026, under BOD 22-01. Users should also review system logs and block any suspicious IPs identified during investigation as per vendor guidance.
Technical Details
- Article Source
- {"url":"https://www.securityweek.com/cisa-urges-immediate-patching-of-exploited-litespeed-cpanel-plugin-zero-day/","fetched":true,"fetchedAt":"2026-05-27T07:03:31.383Z","wordCount":988}
Threat ID: 6a169743e29bf47b50a0eed8
Added to database: 5/27/2026, 7:03:31 AM
Last enriched: 5/27/2026, 7:03:40 AM
Last updated: 5/27/2026, 10:53:16 AM
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.