The images in this article were generated with artificial intelligence. How we publish
A vulnerability of maximum severity has been reported and confirmed as being exploited in real environments in the LiteSpeed User-End plugin for cPanel: CVE-2026-48172(CVSS 10.0). According to the manufacturer, the failure consists of an incorrect allocation of privileges that allows any cPanel user - including an attacker with a compromised account - to invoke the lsws.redisAble function for run arbitrary scripts with root permissions. The problem affects the plugin versions between 2.3 and 2.4.4; the correction is available from version 2.4.5 and LiteSpeed has published more later patches integrated into the recommended package.
The active operating presence increases the immediate risk for shared hosting servers, VPS and any infrastructure using the affected plugin, because the execution as root allows an attacker to install persistent back doors, deploy botnets, miners or ransomware, or take full control of the node. This incident comes weeks after another critical vulnerability in the cPanel ecosystem that was used to distribute Mirai and Ransomware variants, which highlights the ease with which management component failures can become powerful attack vectors.

As urgent measures, and always prioritizing the minimum possible exposure, update immediately to the version of plugin cPanel 2.4.7 and to the plugin WHM 5.3.1.0 or higher as recommended by the supplier. If it is not possible to apply the patch immediately, LiteSpeed proposes to temporarily remove the user plugin; check the official instructions and, before running drastic changes, coordinate with your hosting provider or the operations team to avoid unexpected interruptions. In all cases, contact the LiteSpeed support to receive the commitment indicators (IOC) and the check commands they have published.
In addition to patching or removing the vulnerable component, an incident investigation is essential: search processes and scripts running as root that does not recognize, new or modified crons, unexpected user accounts, webshells and outgoing connections to IPs or unknown domains. Check the Apache / Nginx, cPanel / WHM and authentication records to detect abnormal accesses; rote credentials and keys that may have been compromised and, in the light of the slightest suspicion of commitment, isolate the server and restore it from a validated clean backup.

To minimize the attack surface while applying the remediation, consider applying containment controls: restrict access to cPanel / WHM by IP, strengthen password policies and multifactor authentication, monitor outgoing processes and connections with EDR / NDR tools and maintain unmuted copies of backups. These practices reduce the probability of scaling and spreading from a compromised user account to total system control.
LiteSpeed has accredited researcher David Strydom for the finding and has indicated that, following the incident, additional vectors have been patched in both plugins. For official information and updates, see the manufacturer's security centre and the documentation of the hosting ecosystem. You can start at LiteSpeed security center and review cPanel general ads and recommendations on your official blog: CPanel Blog. For good practice in response and mitigation of intrusions, the OWASP community reference guide may be useful: OWASP.
In summary: try CVE-2026-48172 as a critical priority: park or remove the vulnerable plugin now, investigate any sign of commitment urgently and apply containment controls while strengthening the security position of your hosting environment. If you manage or provide hosting services, tell your customers about the risk and actions taken to contain it.
Related
More news on the same subject.

Anonymous MousKIT phishing platform identified to remove Activation Lock on iPhone and iPad
Cybersecurity researchers have documented a phishing platform as a service aimed at eliminating the protection of Activation Lock from stolen iPhones and iPads, combining forged...

United States U.S. imposes sanctions on Iranian networks linked to MOIS and Mabna in the Economic Outcast operation
The U.S. Treasury Department has launched a new round of financial sanctions against networks linked to Iran, in a campaign that the U.S. authorities describe as a coordinated e...

NemoClaw operating chain exposes Olama to unauthenticated access and alters chat templates
What has happened (confirmed facts): Oasis Security researchers have published a report describing a chain of exploitation against the NemoClaw configuration that can allow a we...

CISA adds CVE-2026-21962 to KEV by remote operation in Oracle HTTP Server and WebLogic
The United States Agency for Cybersecurity and Infrastructure (CISA) has included in its catalogue Known Exploited Vulnerabilities (KEV) the critical failure traced as CVE-2026-...

IA in code generation accelerates OSS dependencies and generates security mediation debt
A recent seminar organized by ActiveState and a survey of 300 security and development leaders in companies in different sectors confirms something that many teams already notic...

They identify WordlistLoader and SynkLoader, intermediate loaders linked to access brokers for
Cybersecurity researchers have identified two new malware families - called WordlistLoader and SynkLoader - used as intermediate stages to deploy later loads and, according to p...

TikTok will pay 400 million for COPPA; 100 M subject to annulment of decree Musical.ly
The U.S. Department of Justice. United States announced payment of $400 million by TikTok to resolve a 2024 lawsuit that accused the platform - owned by ByteDance - of violating...