Skip to content

CVE-2026-48172

CVE

Threat entity extracted from intelligence sources

Frequency
3
occurrences
First Seen
May 23, 2026
Last Seen
June 16, 2026
API
Exploited in Wild
Ransomware Use
Public Exploits
Attack Vector

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

A critical zero-day privilege escalation vulnerability in the LiteSpeed User-End cPanel plugin is being exploited in the wild, allowing authenticated cPanel users to execute arbitrary scripts as root. This flaw, tracked as CVE-2026-48172, has a maximum CVSS score of 10.0 and affects versions from v2...

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding a critical vulnerability (CVE-2026-54420) in the LiteSpeed cPanel user-end plugin, which allows attackers with FTP or web shell access to escalate privileges to root on shared hosting servers using CloudL...

Public Exploits

Checking GitHub for proof-of-concept code…