Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical LiteSpeed Flaw Risks Root Access on Shared Servers

Critical LiteSpeed Flaw Risks Root Access on Shared Servers

Posted on September 15, 2026 By CWS

A significant security flaw has been identified in LiteSpeed Web Server Enterprise, potentially allowing low-privileged users to gain root access on shared hosting servers. cPanel disclosed this vulnerability in an advisory issued on September 14, 2026, urging administrators to upgrade to the latest software version.

Vulnerability Details and Risks

The vulnerability, affecting versions earlier than 6.3.7, poses a threat to shared servers hosting multiple websites on a single machine. An attacker could exploit this flaw to access and modify other sites or the server itself, as highlighted in cPanel’s advisory.

cPanel emphasized the necessity of updating to version 6.3.7, which LiteSpeed released on September 11. This update aims to address the flaw, which could bypass isolation mechanisms like CageFS, a CloudLinux tool designed to restrict each account’s view of the file system.

Update Instructions and Challenges

Administrators are advised to manually update to LiteSpeed version 6.3.7 using the command: /usr/local/lsws/admin/misc/lsup.sh -f -v 6.3.7. This step is crucial since the update may not automatically deploy, as LiteSpeed noted potential delays in the automatic update process.

As of September 15, the LiteSpeed download page still listed version 6.3.6 as the stable release, with no mention of the recent security enhancements in the pre-release 6.4.0 (RC1). It’s important for server administrators to ensure their systems are updated to mitigate potential risks.

Previous Vulnerabilities and Current Concerns

This incident marks the third reported LiteSpeed software vulnerability since May that could allow root access on cPanel servers. Earlier, in May and June, two different vulnerabilities were identified and fixed in the LiteSpeed cPanel plugin, which were actively exploited, according to CVE reports.

Despite the release of version 6.3.7, neither cPanel nor LiteSpeed has provided a workaround for servers unable to update immediately or indicators to check if a server has been compromised. The current advisory also does not mention OpenLiteSpeed, the open-source counterpart, which remains without a corresponding update.

For the security of their web environments, administrators should prioritize these updates and stay informed about potential vulnerabilities, ensuring their systems are safeguarded against unauthorized access.

The Hacker News Tags:CageFS, CloudLinux, cPanel, Exploit, LiteSpeed, root access, security update, shared hosting, Vulnerability, web security

Post navigation

Previous Post: HBO Max Reddit Account Compromised for Malware Ads
Next Post: Leading Serverless Security Solutions for 2026

Related Posts

Fake IT Support Scam Spreads Havoc C2 Framework Fake IT Support Scam Spreads Havoc C2 Framework The Hacker News
 Battering RAM Attack Breaks Intel and AMD Cloud Security Protections $50 Battering RAM Attack Breaks Intel and AMD Cloud Security Protections The Hacker News
New ‘Curly COMrades’ APT Using NGEN COM Hijacking in Georgia, Moldova Attacks New ‘Curly COMrades’ APT Using NGEN COM Hijacking in Georgia, Moldova Attacks The Hacker News
Google Patches Critical Zero-Day Flaw in Chrome’s V8 Engine After Active Exploitation Google Patches Critical Zero-Day Flaw in Chrome’s V8 Engine After Active Exploitation The Hacker News
China-Made Routers Exposed to Critical Security Breaches China-Made Routers Exposed to Critical Security Breaches The Hacker News
Why Non-Human Identity Management is the Next Cybersecurity Frontier Why Non-Human Identity Management is the Next Cybersecurity Frontier The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Leading Serverless Security Solutions for 2026
  • Critical LiteSpeed Flaw Risks Root Access on Shared Servers
  • HBO Max Reddit Account Compromised for Malware Ads
  • China-Linked Hackers Exploit Chrome, Windows Flaws
  • Revolut Exposed by Fake Government Data Requests

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Leading Serverless Security Solutions for 2026
  • Critical LiteSpeed Flaw Risks Root Access on Shared Servers
  • HBO Max Reddit Account Compromised for Malware Ads
  • China-Linked Hackers Exploit Chrome, Windows Flaws
  • Revolut Exposed by Fake Government Data Requests

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark