CISA alert exploited vulnerability in LiteSpeed cPanel allows to climb to root urgent patch 2.4.8

Author: Published 3 min de lectura 277 reading

The images in this article were generated with artificial intelligence. How we publish

The US Agency for Infrastructure and Cybersecurity. USA (CISA) has placed the fault known as CVE-2026-48172 in its catalogue of exploited vulnerabilities (KEV) and has ordered federal agencies to remeasure systems within three days BOD 26-04 because it is an actively exploited vulnerability that allows root climbing in shared hosting environments.

The vector affects the LiteSpeed user plugin for cPanel in versions prior to the 2.4.8 and comes from a weakness of "symbolic link tracking" (following symlink) that, when combined with FTP access or already present web shells, allows attackers to get out of isolation cages such as CloudLinux / CageFS and obtain total server control.

CISA alert exploited vulnerability in LiteSpeed cPanel allows to climb to root urgent patch 2.4.8
Image generated with IA.

LiteSpeed confirmed active operation in early June and published an urgent patch; if you administer cPanel / WHM servers you should prioritize the plugin update to version 2.4.8 or higher immediately. See the manufacturer's instructions to apply the patch: Safety notice for LiteSpeed.

As a first operational step, check whether your server has been potentially compromised by running the evidence search on the loops that the developer himself recommends: grep -rE'cpanel _ jsonapi _ func = (generateEcCert h124; packageUserSize) h124; cert _ action _ entry. * geneccert '/ usr / local / cpanel / logs / var / cpanel / logs / 2 > / dev / null. If this command returns lines, investigate those IPs and actions with top priority.

If you detect suspicious activity, isolate the affected accounts and create forensic images of the system before cleaning; keep logs and metadata for traceability. Consider additional immediate actions such as disabling FTP if not required, rotating credentials (FTP, hosting accounts, SSH keys and API), and reviewing cronjobs, authorized keys (~ / .ssh / authorised _ keys), and web files by web shells.

To reduce risk while patching, block public access to panels and administrative services with IP or VPN access controls, implement temporary rules in the WAF to monitor and block abuse patterns and limit writing permits in sensitive directories. If your hosting provider manages these components, it requires an update and an audit of commitments.

This CISA order highlights the current dynamics: vulnerabilities in components packed with control panels are quickly exploited on a scale. Multiuser environments are particularly dangerous because a compromised account can become a trampoline to attack all server customers.

CISA alert exploited vulnerability in LiteSpeed cPanel allows to climb to root urgent patch 2.4.8
Image generated with IA.

If you belong to the public sector or attend to government customers, non-compliance with BOD 26-04 may have regulatory and operational consequences; check the CISA alert for details and time frames: CISA Alert (June 15). For technical reference on CVE, see the NVD register: CVE-2026-48172 in NVD.

Finally, it plans preventive actions in the medium term: automate patch management in critical infrastructure, strengthen monitoring (SIEM / EDR) for early detection of side movements and team / break & attack simulation network tests that validate controls before the attackers exploit them.

If you need to, I can help you to write an immediate response checklist adapted to your environment (shared hosting provider, VPS or managed infrastructure) or propose search requests and rules for your OEM based on the known indicators of this operation.

Coverage

Related

More news on the same subject.