Critical LiteSpeed Web Server Enterprise Flaw Could Grant Root Access on Shared Hosting
cPanel warns of a critical vulnerability that allows low-privilege users to gain root access on shared servers.

Key Takeaways
- A critical vulnerability in LiteSpeed Web Server Enterprise could allow a low-privilege user to gain root access on shared-hosting servers.
- cPanel published an advisory on September 14, 2026, warning of the flaw.
- The vulnerability could lead to full server compromise, affecting all hosted websites.
Related Security News

Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials
The maintainers of the official MCP Python SDK disclosed a security vulnerability that could allow a malicious server to trick applications into divulging OAuth credentials. The issue affects the handling of client secrets, authorization codes, and PKCE proof keys when communicating with token endpoints.

One Packet Can Crash OT Servers in Industrial Sectors
A high-severity zero-day vulnerability in the TDengine time-series database allows a single malformed packet to crash OT servers, potentially disrupting industrial, IoT, energy, and automotive operations. Details regarding exploitation status and remediation remain limited.



