Find notable cyber news and cases, enriched with sources, timelines, and signals.

LiteSpeed Web Server Enterprise 6.3.7 security release

Security Patch Release
First reported
Last updated
Happening score
H score 32
1 unique sources, 1 articles

Summary

Hide ▲

LiteSpeed published 6.3.7 for LiteSpeed Web Server Enterprise, and cPanel urged administrators to install it to address a flaw affecting versions before 6.3.7. The release is the immediate update path for shared-hosting environments where one low-privilege account could reach root access if the flaw is present. LiteSpeed said the release may take time to reach auto-update, making the manual install command the recommended response.

Related Happenings

Gitea security patch release for CVE-2026-59774

Security Patch Release
H score65 First: 05.08.2026 14:04 Last: 05.08.2026 14:04 Sources 1

About this happening: Gitea 1.27.1 is a security patch release that closes CVE-2026-59774 and CVE-2026-60004, reducing exposure for self-hosted Gitea deployments. The update fixes a C...

OpenWrt security patch release for CVE-2026-53921

Security Patch Release
H score37 First: 28.07.2026 15:56 Last: 28.07.2026 15:56 Sources 1

About this happening: OpenWrt released 24.10.8 and 25.12.5 to close a critical DHCPv6 stack overflow in odhcpd, reducing the risk of root code execution on exposed routers. The...

CISA KEV order for FCEB agencies on LiteSpeed cPanel flaw

Public Sector Action
H score36 First: 16.06.2026 13:47 Last: 16.06.2026 13:47 Sources 1

About this happening: CISA added the LiteSpeed cPanel user-end plugin flaw to KEV and ordered Federal Civilian Executive Branch agencies to secure systems within three days under ...

CISA KEV mitigation for LiteSpeed cPanel Plugin (CVE-2026-54420)

Advisory/Mitigation
H score38 First: 16.06.2026 08:41 Last: 16.06.2026 08:41 Sources 1

About this happening: CISA put CVE-2026-54420 in LiteSpeed cPanel Plugin on the KEV catalog, ordering FCEB agencies to apply fixes by June 18, 2026. The flaw is a CVSS 8.5 privile...

LiteSpeed cPanel user-end plugin urgent security update (CVE-2026-48172)

Security Patch Release
H score42 First: 27.05.2026 13:06 Last: 27.05.2026 13:06 Sources 1

About this happening: LiteSpeed released urgent security updates for the cPanel user-end plugin after CVE-2026-48172 was found to be actively exploited, reducing exposure for systems ru...

Latest development: 16.06.2026 13:47

CISA added CVE-2026-48172/CVE-2026-54420 in the LiteSpeed cPanel user-end plugin to the Known Exploited Vulnerabilities Catalog and ordered Federal Civilian Executive Branch agencies to secure affected servers within three days under BOD 26-04. The affected plugin versions before 2.4.8 are described as actively exploited, with FTP or web shell access enabling root escalation on shared hosting servers running CloudLinux/CageFS.

Timeline

  1. 14.09.2026 03:00 1 articles · 1d ago

    cPanel warns that a LiteSpeed Web Server Enterprise flaw can grant root access on shared hosting

    Initial Disclosure

    cPanel warned on September 14 that a critical vulnerability in LiteSpeed Web Server Enterprise could let a low-privilege website user on a shared-hosting server gain root access and bypass isolation controls such as CageFS. The advisory said the flaw affects versions before 6.3.7 and did not provide a CVE identifier, severity score, exploit details, or a workaround for servers that cannot update immediately.

    Show sources
  2. 11.09.2026 03:00 2 articles · 4d ago

    LiteSpeed publishes 6.3.7 to fix a root-access flaw in Web Server Enterprise

    Mitigation Patch Update

    LiteSpeed published version 6.3.7 for LiteSpeed Web Server Enterprise on September 11, closing a flaw affecting versions before 6.3.7. Administrators were told to install the release manually with /usr/local/lsws/admin/misc/lsup.sh -f -v 6.3.7 because the update may not reach auto-update immediately.

    Show sources