LiteSpeed security advisory

Incident Report for Liquid Web - Services

Monitoring

All accessible Fully and Core-Managed servers running outdated versions of LiteSpeed have been patched to version 6.3.7. The same webserver service that was in use before the LiteSpeed upgrade remains in use afterwards.

If you have any questions or concerns, please contact support@liquidweb.com.
Posted Sep 15, 2026 - 00:19 EDT

Investigating

WebPros (cPanel) posted news regarding a critical privilege-escalation vulnerability within the LiteSpeed software. A malicious website user could potentially gain root-level access to the server (even bypassing account isolation controls such as CageFS).

More Information can be found here:
https://support.cpanel.net/hc/en-us/articles/43483286674583-Security-LiteSpeed-Enterprise-security-advisory-September-14-2026

We will attempt to update LiteSpeed to the patched version (6.3.7) where we are able to via Automation. Regardless, please ensure your Litespeed is up-to-date.

If you have any questions or concerns, please contact support@liquidweb.com
Posted Sep 14, 2026 - 16:31 EDT