CISA Gives Feds Days to Patch cPanel Flaw
CISA just ordered federal agencies to patch a critical flaw in the LiteSpeed cPanel plugin within four days because attackers are already using it.
CVE-2026-48172 lets unprivileged attackers run scripts as root. CVSS 10.0 and actively exploited.
Affects LiteSpeed User-End cPanel Plugin versions 2.3 through 2.4.4. Federal agencies and any public-facing cPanel installs running the plugin must act.
CISA urged all defenders to prioritize patching.
