The LiteSpeed cPanel Plugin has a UNIX Symbolic Link (Symlink) Following Vulnerability. This CVE was published on 2026-06-15T00:00:00.000Z and has not been modified since then. The vulnerability allows attackers to potentially manipulate files or directories. System administrators and security teams should assess exposure and apply mitigations according to vendor instructions. The NVD entry is currently . [truncated]
Known exploitedLiteSpeed TechnologiesCVE published 2026-05-26
CVE-2026-48172 is a critical flaw in the LiteSpeed User-End cPanel Plugin before 2.4.5 that may allow privilege escalation, potentially to root. The supplied record says it was exploited in the wild in May 2026. LiteSpeed’s parent WHM plugin is described as unaffected. For exposed cPanel environments, this should be treated as an urgent patch-and-investigate issue.
HIGHLiteSpeed TechnologiesCVE published 2026-03-16
CVE-2026-31386 is an OS command injection vulnerability in OpenLiteSpeed and LSWS Enterprise provided by LiteSpeed Technologies. An attacker with administrative privilege can execute an arbitrary OS command.