U.S. CISA adds LiteSpeed cPanel Plugin flaw to its Known Exploited Vulnerabilities catalog


U.S. CISA adds LiteSpeed cPanel Plugin flaw to its Known Exploited Vulnerabilities catalog

Pierluigi Paganini
May 28, 2026

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds LiteSpeed cPanel Plugin flaw to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the LiteSpeed cPanel Plugin flaw CVE-2026-48172 to its Known Exploited Vulnerabilities (KEV) catalog.

CVE-2026-48172 (CVSS score of 10.0) affects the LiteSpeed User-End cPanel plugin before version 2.4.5 and allows privilege escalation, potentially up to root, and has been exploited in the wild. The flaw comes from improper handling of Redis enable/disable functions. Attackers can abuse it to run unauthorized actions on affected servers. Detection involves searching cPanel logs for suspicious Redis-related API calls, while mitigation requires upgrading to at least version 2.4.7 and reviewing logs and IP activity for signs of compromise.

LiteSpeed released emergency patches for CVE-2026-48172, warning that the flaw is actively exploited in cPanel user-end plugin versions v2.3 through v2.4.4. Admins should update immediately and check logs with a provided grep command to detect suspicious IP activity and investigate possible compromise.

“Any cPanel user (including an attacker or a compromised account) may exploit the lsws.redisAble function to execute arbitrary scripts as root.” reads the advisory. “This vulnerability is being actively exploited, and poses a risk for all user-end plugin versions between v2.3 and v2.4.4.”

Run this command to check if your server is affected:

grep -rE "cpanel_jsonapi_func=redisAble" /var/cpanel/logs /usr/local/cpanel/logs/ 2>/dev/null

If it returns no output, your server is not affected. If it returns results, review the listed IPs, verify if they are legitimate, block suspicious ones, and check system logs to assess any potential impact or unauthorized actions.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix the vulnerabilities by May 29, 2026.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)







Source link

Leave a Reply

Subscribe to Our Newsletter

Get our latest articles delivered straight to your inbox. No spam, we promise.

Recent Reviews



Nothing has quietly fixed one of the most annoying aspects of Essential Space. The company has enabled cloud backup for content stored in the feature, meaning it is no longer tied to a single device. 

It will now travel with you, should you choose to switch from one Nothing or CMF device to another, synced via your Nothing account. 

Essential Space now stays with you.

Cloud storage keeps your notes, screenshots, voice captures, images, tasks and summaries backed up and synced through your Nothing account.

So when you move to a new phone or reset your device, your Space comes with you. pic.twitter.com/JSX4Ho4EYN

— Essential (@essential) April 27, 2026

What exactly is backed up?

Everything you’ve ever captured with the Essential Key is eligible for backup. This includes your audio recording, quick screenshots, saved images, email or document summaries — essentially the entire Essential Space content library. The feature also takes care of offline captures.

If auto-updates for apps are enabled in the Google Play Store, the app should receive the new feature automatically. However, if it doesn’t, you can update the app manually to enable cloud backup. 

Once the update is installed, you can head to Essential Space > Profile > Storage, and select Backup to set it up. The feature’s backend is based on Google’s cloud infrastructure (not Google Drive); it doesn’t count toward your personal Google storage quota.

Furthermore, the data remains fully GDPR-compliant, implying that only you can access the content.

Rolling out from today to all 2025–2026 Nothing and CMF phones that support the Essential Key.

Update Essential Space from the Google Play Store, or turn on auto-update to get it automatically.

— Essential (@essential) April 27, 2026

Which devices support the feature?

For now, cloud backup for Essential Space is rolling out to all 2025-2026 Nothing and CMF phones that feature the Essential Key. To my recollection, this includes the Nothing Phone (3), Phone (4a), Phone (4a) Pro, and the CMF Phone 2 Pro, among others. 

Older devices without the Essential Key are not supported, at least for now. A gap worth flagging is that there’s no web or desktop version of Essential Space, a fact the company has already acknowledged. 

For Nothing to create a functional ecosystem of devices, the Essential Space cloud backup is quite essential. Without it, every upgrade or device reset was a potential data loss event, but the cloud backup suggests that Nothing is on the right track. 



Source link