Scheduled maintenance is currently in progress. We will provide updates as necessary.
Posted Sep 14, 2026 - 18:30 EDT
Scheduled
A critical privilege-escalation vulnerability has been identified in LiteSpeed Web Server Enterprise. On shared-hosting servers, a malicious low-privilege website user could potentially gain root-level access to the server.
This issue can bypass expected account isolation controls, including CageFS, allowing a malicious website user to potentially escape its restricted environment and gain root-level access to the server.
Impact Currently affected versions are LiteSpeed Web Server Enterprise versions prior to v6.3.7.
All cpanel and directadmin shared hosting servers have been upgraded to 6.3.7.
Users who have litespeed enterprise installed: Please run the following command to perform an update to LiteSpeed v6.3.7:
/usr/local/lsws/admin/misc/lsup.sh -f -v 6.3.7
Posted Sep 14, 2026 - 18:26 EDT
This scheduled maintenance affects: Services (Webhosting, Storage).