🔴
CISA KEV Alert — Active Real-World Exploitation Confirmed
This vulnerability is in the CISA Known Exploited Vulnerabilities catalog and is being actively exploited right now.

LiteSpeed cPanel Plugin Privilege Escalation to Root (CVE-2026-48172) | MSSP Advisory

Critical🔴 KEV ALERTConfirmed
DateMay 26, 2026
CVECVE-2026-48172
📋Executive Summary
CISA has added CVE-2026-48172 to the Known Exploited Vulnerabilities catalog, targeting LiteSpeed cPanel plugins with a privilege escalation flaw that grants root access. Any cPanel user can exploit this vulnerability to execute arbitrary scripts with full system privileges.
⚠️Why It Matters for MSSPs
Your hosting infrastructure and client web hosting environments running LiteSpeed with cPanel are directly exposed to immediate root compromise. Client websites hosted on affected systems face complete takeover risk, and your advisory silence creates liability when the inevitable breach notifications start flowing.
Recommended Action
Inventory all client hosting environments using LiteSpeed cPanel plugins within 24 hours and apply vendor patches immediately. Contact hosting providers for client sites you do not directly control and document the notification for compliance records.
🔒
Partner content — get access free
The recommended action is included in your white-labeled advisory — ready to send to clients under your name.
Get your first advisory free →
🏷️Threat Category
Vulnerability Disclosure

Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.