CVE-2026-48172 is a vulnerability tracked across 2 threat clusters and 3 intelligence report mentions on ThreatCluster. First observed May 23, 2026; most recent activity June 16, 2026.
A critical zero-day privilege escalation vulnerability in the LiteSpeed User-End cPanel plugin is being exploited in the wild, allowing authenticated cPanel users to execute arbitrary scripts as root. This flaw, tracked…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding a critical vulnerability (CVE-2026-54420) in the LiteSpeed cPanel user-end plugin, which allows attackers with FTP or web…