• News/
  • bleepingcomputer-20260527100617

CISA gives feds 4 days to patch actively exploited cPanel plugin flaw

BleepingComputer
·
Sergiu Gatlan
·
Published May 27, 2026
·
Updated

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has given U.S. federal agencies four days to secure their servers against a critical vulnerability in the LiteSpeed cPanel user-end plugin, which is actively being exploited in attacks. Tracked as CVE-2026-48172, this privilege escalation vulnerability is related to the mishandling of Redis enable/disable features and was found in the lsws.redisAble function. The vulnerability stems from an incorrect privilege assignment weakness that enables remote attackers with no privileges to execute arbitrary scripts with root privileges. LiteSpeed released urgent security updates on Thursday to address the flaw, warning users to update the cPanel user-end plugin (bundled with the WHM plugin) to the latest version. Users are advised to use the following command to check if their server is vulnerable to CVE-2026-48172 attacks: "This vulnerability is being actively exploited, and poses a risk for all user-end plugin versions between v2.3 and v2.4.4," the LiteSpeed team noted. "If this command results in any output, we recommend you examine the IPs in the list, determine if they are valid, and if not, block them. To determine any damage done, examine the system logs for any actions taken by the detected IPs." ​​​On Tuesday, CISA added the security flaw to its catalog of vulnerabilities exploited in attacks and ordered U.S. federal agencies to patch their systems by midnight on Friday, May 29, as mandated by Binding Operation...

Read full article

Affected Software

1 affected component
LiteSpeed cPanel user-end plugin>=v2.3<=v2.4.4
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical vulnerability in the LiteSpeed cPanel user-end plugin that is being actively exploited and requires prompt action from federal agencies.

2

What is the deadline given by CISA for patching the vulnerability?

CISA has given federal agencies four days to patch the vulnerability in the LiteSpeed cPanel user-end plugin.

3

What is the CVE identifier for the vulnerability discussed in the article?

The vulnerability is tracked as CVE-2026-48172.

4

What type of vulnerability is associated with the LiteSpeed cPanel plugin?

The vulnerability is a privilege escalation flaw.

5

Who is affected by this vulnerability?

U.S. federal agencies are specifically targeted and urged to secure their servers against this vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203