DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 06:03:37ZSOURCES: 14CRITICAL: 15
⚠ ACTIVE ALERTS
SYLVANITE CRITICAL — SYLVANITE is a newly named Dragos-tracked threat group identified as a dedicated… /// @MsftSecIntel CRITICAL — We are tracking TeamPCP (UNC6780) activity following the GitHub internal repository… /// @GossiTheDog CRITICAL — The GitHub / TeamPCP breach is now being monetized on BreachForums. Listing is up — $95k… /// @struppigel CRITICAL — SUPPLY CHAIN ALERT: Laravel-Lang PHP packages backdoored May 22-23 via hijacked GitHub… /// @MalwareHunterTeam CRITICAL — Seeing fresh DebugElevator stealer log batches already appearing for sale on Exploit.in —…
15Critical Threats
8Active CVEs
0IOCs Tracked
0New Advisories
TLP:WHITEVULNERABILITY BRIEF // CVE-2026-48172PUBLISHED: 2026-05-21
CRITICALCVE-2026-48172

LiteSpeed cPanel Plugin Root Privilege Escalation

VENDOR: LiteSpeed Technologies//PRODUCT: LiteSpeed User-End cPanel Plugin
10
CRITICAL
CVSS 3.1
PATCH STATUS
PATCH AVAILABLE
EXPLOIT STATUS
LIMITED EXPLOITATION

An incorrect privilege assignment (CWE-266) in the lsws.redisAble JSON-API function allows any authenticated cPanel user — including attackers with compromised shared-hosting accounts — to execute arbitrary scripts as root with a single malformed API call requiring no race condition or authentication gap. LiteSpeed confirmed active in-the-wild exploitation with opportunistic automated scanning targeting web hosting environments broadly. cPanel forced a fleet-wide emergency uninstall five hours before its scheduled patch window. Fixed in version 2.4.5 (recommend 2.4.7 bundled with WHM Plugin 5.3.1.0).

Attack Vector
NETWORK
Attack Complexity
LOW
Privs Required
LOW
User Interaction
NONE
Scope / Impact
CHANGED
C:H · I:H · A:H
AFFECTED VERSIONSLiteSpeed User-End cPanel Plugin versions 2.3 through 2.4.4 (WHM plugin not affected)
  • https://thehackernews.com/2026/05/litespeed-cpanel-plugin-cve-2026-48172.html
  • https://www.rescana.com/post/critical-active-exploitation-alert-cve-2026-48172-in-litespeed-cpanel-plugin-enables-root-privilege-escalation
  • https://threat-modeling.com/vulnerability-intelligence-report-may-23-2026/
SHARE BRIEF:✕ Post on Xin Share on LinkedIn