Nicolas Krassas[verified]@DinosnActive Exploitation
The article indicates that CVE‑2026‑48172 in the LiteSpeed cPanel plugin is actively exploited, enabling attackers to execute scripts with root privileges.
モーくん🐮|WordPress × セキュリティ[verified]@accell_mo_kunActive Exploitation
CVE‑2026‑48172, a privilege‑escalation flaw in LiteSpeed cPanel, has been added to CISA KEV and is actively exploited; administrators are urged to update to a patched version before the 5/29 deadline.
yousukezan[verified]@yousukezanActive Exploitation
CVE‑2026‑48172 in the LiteSpeed cPanel Plugin is actively exploited, enabling remote attackers to elevate privileges and potentially seize full control of the server. A patch is available and an urgent update is recommended.
piyokango[verified]@piyokangoActive Exploitation
CISA has added CVE-2026-48172 to its Known Exploited Vulnerabilities catalog, confirming that the LiteSpeed cPanel Plugin vulnerability is actively exploited; vendor has issued a security update.
モーくん🐮|WordPress × セキュリティ[verified]@accell_mo_kunPatch
The tweet alerts operators to the imminent CISA KEV deadline for CVE‑2026‑48172 and urges them to verify and apply the patch or schedule remediation promptly.
Elusive[verified]@ElusivePrivacyActive Exploitation
The post reports that CVE‑2026‑48172, a privilege‑escalation flaw in LiteSpeed’s cPanel Plugin, is actively exploited, letting users run arbitrary scripts as root via the lsws.redisAble function.
Blue Team News[verified]@blueteamsec1Exploit
The tweet announces that CVE‑2026‑48172 was exploited to run scripts as root and links to likely PoC or exploit details, indicating both the existence of a PoC and active exploitation, but without vendor mitigation information.
Tobibur Rahman[verified]@tobi8urPatch
CISA has mandated agencies to patch or remove the LiteSpeed cPanel user‑end plugin due to zero‑day attacks on CVE‑2026‑48172 that allow root‑level script execution.