LiteSpeed Web Server Enterprise 6.3.7 security release
Security Patch Release
Summary
Hide ▲
Show ▼
LiteSpeed published 6.3.7 for LiteSpeed Web Server Enterprise, and cPanel urged administrators to install it to address a flaw affecting versions before 6.3.7. The release is the immediate update path for shared-hosting environments where one low-privilege account could reach root access if the flaw is present. LiteSpeed said the release may take time to reach auto-update, making the manual install command the recommended response.
Related Happenings
Gitea security patch release for CVE-2026-59774
Security Patch Release
H score65
First: 05.08.2026 14:04
Last: 05.08.2026 14:04
Sources 1
About this happening:
Gitea 1.27.1 is a security patch release that closes CVE-2026-59774 and CVE-2026-60004, reducing exposure for self-hosted Gitea deployments. The update fixes a C...
Gitea security patch release for CVE-2026-59774
Security Patch ReleaseAbout this happening: Gitea 1.27.1 is a security patch release that closes CVE-2026-59774 and CVE-2026-60004, reducing exposure for self-hosted Gitea deployments. The update fixes a C...
OpenWrt security patch release for CVE-2026-53921
Security Patch Release
H score37
First: 28.07.2026 15:56
Last: 28.07.2026 15:56
Sources 1
About this happening:
OpenWrt released 24.10.8 and 25.12.5 to close a critical DHCPv6 stack overflow in odhcpd, reducing the risk of root code execution on exposed routers. The...
OpenWrt security patch release for CVE-2026-53921
Security Patch ReleaseAbout this happening: OpenWrt released 24.10.8 and 25.12.5 to close a critical DHCPv6 stack overflow in odhcpd, reducing the risk of root code execution on exposed routers. The...
CISA KEV order for FCEB agencies on LiteSpeed cPanel flaw
Public Sector Action
H score36
First: 16.06.2026 13:47
Last: 16.06.2026 13:47
Sources 1
About this happening:
CISA added the LiteSpeed cPanel user-end plugin flaw to KEV and ordered Federal Civilian Executive Branch agencies to secure systems within three days under ...
CISA KEV order for FCEB agencies on LiteSpeed cPanel flaw
Public Sector ActionAbout this happening: CISA added the LiteSpeed cPanel user-end plugin flaw to KEV and ordered Federal Civilian Executive Branch agencies to secure systems within three days under ...
CISA KEV mitigation for LiteSpeed cPanel Plugin (CVE-2026-54420)
Advisory/Mitigation
H score38
First: 16.06.2026 08:41
Last: 16.06.2026 08:41
Sources 1
About this happening:
CISA put CVE-2026-54420 in LiteSpeed cPanel Plugin on the KEV catalog, ordering FCEB agencies to apply fixes by June 18, 2026. The flaw is a CVSS 8.5 privile...
CISA KEV mitigation for LiteSpeed cPanel Plugin (CVE-2026-54420)
Advisory/MitigationAbout this happening: CISA put CVE-2026-54420 in LiteSpeed cPanel Plugin on the KEV catalog, ordering FCEB agencies to apply fixes by June 18, 2026. The flaw is a CVSS 8.5 privile...
LiteSpeed cPanel user-end plugin urgent security update (CVE-2026-48172)
Security Patch Release
H score42
First: 27.05.2026 13:06
Last: 27.05.2026 13:06
Sources 1
About this happening:
LiteSpeed released urgent security updates for the cPanel user-end plugin after CVE-2026-48172 was found to be actively exploited, reducing exposure for systems ru...
LiteSpeed cPanel user-end plugin urgent security update (CVE-2026-48172)
Security Patch ReleaseAbout this happening: LiteSpeed released urgent security updates for the cPanel user-end plugin after CVE-2026-48172 was found to be actively exploited, reducing exposure for systems ru...
Latest development: 16.06.2026 13:47
CISA added CVE-2026-48172/CVE-2026-54420 in the LiteSpeed cPanel user-end plugin to the Known Exploited Vulnerabilities Catalog and ordered Federal Civilian Executive Branch agencies to secure affected servers within three days under BOD 26-04. The affected plugin versions before 2.4.8 are described as actively exploited, with FTP or web shell access enabling root escalation on shared hosting servers running CloudLinux/CageFS.
Timeline
-
14.09.2026 03:00 1 articles · 1d ago
cPanel warns that a LiteSpeed Web Server Enterprise flaw can grant root access on shared hosting
Initial DisclosurecPanel warned on September 14 that a critical vulnerability in LiteSpeed Web Server Enterprise could let a low-privilege website user on a shared-hosting server gain root access and bypass isolation controls such as CageFS. The advisory said the flaw affects versions before 6.3.7 and did not provide a CVE identifier, severity score, exploit details, or a workaround for servers that cannot update immediately.
Show sources
- LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server — thehackernews.com — 15.09.2026 09:52
-
11.09.2026 03:00 2 articles · 4d ago
LiteSpeed publishes 6.3.7 to fix a root-access flaw in Web Server Enterprise
Mitigation Patch UpdateLiteSpeed published version 6.3.7 for LiteSpeed Web Server Enterprise on September 11, closing a flaw affecting versions before 6.3.7. Administrators were told to install the release manually with /usr/local/lsws/admin/misc/lsup.sh -f -v 6.3.7 because the update may not reach auto-update immediately.
Show sources
- LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server — thehackernews.com — 15.09.2026 09:52
- LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server — thehackernews.com — 15.09.2026 09:52