CISA Urges Immediate Patching of Exploited LiteSpeed cPanel Plugin Zero-Day
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent call for federal agencies to patch a critical vulnerability in the LiteSpeed user-end plugin for cPanel. The vulnerability, identified as CVE-2026-48172, is a privilege escalation issue that allows attackers to execute arbitrary scripts with root privileges. LiteSpeed has already addressed the flaw in version 2.4.5 of the plugin, but it has been actively exploited as a zero-day vulnerability. CISA has added this vulnerability to its Known Exploited Vulnerabilities catalog and is urging agencies to patch or remove the vulnerable plugin versions by May 29, in accordance with Binding Operational Directive 22-01.