The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has given U.S. federal agencies four days to secure their servers against a critical vulnerability in the LiteSpeed cPanel user-end plugin, which is actively being exploited in attacks. Tracked as CVE-2026-48172, this privilege escalation vulnerability is related to the mishandling of Redis enable/disable features and was found in the lsws.redisAble function. The vulnerability stems from an incorrect privilege assignment weakness that enables remote attackers with no privileges to execute arbitrary scripts with root privileges. LiteSpeed released urgent security updates on Thursday to address the flaw, warning users to update the cPanel user-end plugin (bundled with the WHM plugin) to the latest version. Users are advised to use the following command to check if their server is vulnerable to CVE-2026-48172 attacks: "This vulnerability is being actively exploited, and poses a risk for all user-end plugin versions between v2.3 and v2.4.4," the LiteSpeed team noted. "If this command results in any output, we recommend you examine the IPs in the list, determine if they are valid, and if not, block them. To determine any damage done, examine the system logs for any actions taken by the detected IPs." On Tuesday, CISA added the security flaw to its catalog of vulnerabilities exploited in attacks and ordered U.S. federal agencies to patch their systems by midnight on Friday, May 29, as mandated by Binding Operation...
CISA gives feds 4 days to patch actively exploited cPanel plugin flaw
BleepingComputer
·Sergiu Gatlan
·Published May 27, 2026
·Updated
Affected Software
1 affected component
LiteSpeed cPanel user-end plugin>=v2.3<=v2.4.4
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a critical vulnerability in the LiteSpeed cPanel user-end plugin that is being actively exploited and requires prompt action from federal agencies.
2
What is the deadline given by CISA for patching the vulnerability?
CISA has given federal agencies four days to patch the vulnerability in the LiteSpeed cPanel user-end plugin.
3
What is the CVE identifier for the vulnerability discussed in the article?
The vulnerability is tracked as CVE-2026-48172.
4
What type of vulnerability is associated with the LiteSpeed cPanel plugin?
The vulnerability is a privilege escalation flaw.
5
Who is affected by this vulnerability?
U.S. federal agencies are specifically targeted and urged to secure their servers against this vulnerability.