Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical LiteSpeed Flaw Risks Root Access on Shared Servers

Critical LiteSpeed Flaw Risks Root Access on Shared Servers

Posted on September 15, 2026 By CWS

A significant security flaw has been identified in LiteSpeed Web Server Enterprise, potentially allowing low-privileged users to gain root access on shared hosting servers. cPanel disclosed this vulnerability in an advisory issued on September 14, 2026, urging administrators to upgrade to the latest software version.

Vulnerability Details and Risks

The vulnerability, affecting versions earlier than 6.3.7, poses a threat to shared servers hosting multiple websites on a single machine. An attacker could exploit this flaw to access and modify other sites or the server itself, as highlighted in cPanel’s advisory.

cPanel emphasized the necessity of updating to version 6.3.7, which LiteSpeed released on September 11. This update aims to address the flaw, which could bypass isolation mechanisms like CageFS, a CloudLinux tool designed to restrict each account’s view of the file system.

Update Instructions and Challenges

Administrators are advised to manually update to LiteSpeed version 6.3.7 using the command: /usr/local/lsws/admin/misc/lsup.sh -f -v 6.3.7. This step is crucial since the update may not automatically deploy, as LiteSpeed noted potential delays in the automatic update process.

As of September 15, the LiteSpeed download page still listed version 6.3.6 as the stable release, with no mention of the recent security enhancements in the pre-release 6.4.0 (RC1). It’s important for server administrators to ensure their systems are updated to mitigate potential risks.

Previous Vulnerabilities and Current Concerns

This incident marks the third reported LiteSpeed software vulnerability since May that could allow root access on cPanel servers. Earlier, in May and June, two different vulnerabilities were identified and fixed in the LiteSpeed cPanel plugin, which were actively exploited, according to CVE reports.

Despite the release of version 6.3.7, neither cPanel nor LiteSpeed has provided a workaround for servers unable to update immediately or indicators to check if a server has been compromised. The current advisory also does not mention OpenLiteSpeed, the open-source counterpart, which remains without a corresponding update.

For the security of their web environments, administrators should prioritize these updates and stay informed about potential vulnerabilities, ensuring their systems are safeguarded against unauthorized access.

The Hacker News Tags:CageFS, CloudLinux, cPanel, Exploit, LiteSpeed, root access, security update, shared hosting, Vulnerability, web security

Post navigation

Previous Post: HBO Max Reddit Account Compromised for Malware Ads
Next Post: Leading Serverless Security Solutions for 2026

Related Posts

F5 Fixes Critical NGINX Vulnerabilities Allowing Code Execution F5 Fixes Critical NGINX Vulnerabilities Allowing Code Execution The Hacker News
Phishing 3.0: AI’s Role in Modern Cyber Security Phishing 3.0: AI’s Role in Modern Cyber Security The Hacker News
New RCEs, Darknet Busts, Kernel Bugs & 25+ More Stories New RCEs, Darknet Busts, Kernel Bugs & 25+ More Stories The Hacker News
CISA Adds Actively Exploited Sierra Wireless Router Flaw Enabling RCE Attacks CISA Adds Actively Exploited Sierra Wireless Router Flaw Enabling RCE Attacks The Hacker News
Critical Cisco Flaws Fixed: IMC and SSM Security Updates Critical Cisco Flaws Fixed: IMC and SSM Security Updates The Hacker News
SecAlerts Cuts Through the Noise with a Smarter, Faster Way to Track Vulnerabilities SecAlerts Cuts Through the Noise with a Smarter, Faster Way to Track Vulnerabilities The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Leading Kubernetes Security Tools for 2026
  • HBO Max’s Reddit Hacked for Malware Distribution
  • Leading Serverless Security Solutions for 2026
  • Critical LiteSpeed Flaw Risks Root Access on Shared Servers
  • HBO Max Reddit Account Compromised for Malware Ads

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Leading Kubernetes Security Tools for 2026
  • HBO Max’s Reddit Hacked for Malware Distribution
  • Leading Serverless Security Solutions for 2026
  • Critical LiteSpeed Flaw Risks Root Access on Shared Servers
  • HBO Max Reddit Account Compromised for Malware Ads

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark