Liquid Web Status · History · Incident #136845

RESOLVED

LiteSpeed security advisory

Minor · Started Sep 14, 2026 · 4:31 PM

  • Duration

    17h 17m

  • Severity

    Minor

  • Detection lead

  • User reports

Summary

LiteSpeed security advisory

All accessible Fully Managed and Core Managed servers running outdated versions of LiteSpeed have been successfully updated to the patched version, 6.3.7. Services have remained operational, and no additional issues have been identified during monitoring. This incident is now resolved. If you have any questions or concerns, please contact support@liquidweb.com.


  • Started

    Sep 14, 2026 · 4:31 PM

  • Resolved

    Sep 15, 2026 · 9:49 AM

  • Duration

    17h 17m

  • Severity

    Minor

Event timeline

How this incident unfolded

  • Investigating

    Sep 14 · 4:31 PM Liquid Web

    WebPros (cPanel) posted news regarding a critical privilege-escalation vulnerability within the LiteSpeed software. A malicious website user could potentially gain root-level access to the server (even bypassing account isolation controls such as CageFS). More Information can be found here: https://support.cpanel.net/hc/en-us/articles/43483286674583-Security-LiteSpeed-Enterprise-security-advisory-September-14-2026 We will attempt to update LiteSpeed to the patched version (6.3.7) where we are able to via Automation. Regardless, please ensure your Litespeed is up-to-date. If you have any questions or concerns, please contact support@liquidweb.com

  • Monitoring

    Sep 15 · 12:19 AM Liquid Web

    All accessible Fully and Core-Managed servers running outdated versions of LiteSpeed have been patched to version 6.3.7. The same webserver service that was in use before the LiteSpeed upgrade remains in use afterwards. If you have any questions or concerns, please contact support@liquidweb.com.

  • Resolved

    Sep 15 · 9:49 AM Liquid Web

    All accessible Fully Managed and Core Managed servers running outdated versions of LiteSpeed have been successfully updated to the patched version, 6.3.7. Services have remained operational, and no additional issues have been identified during monitoring. This incident is now resolved. If you have any questions or concerns, please contact support@liquidweb.com.

Get alerted before the next Liquid Web outage.

Pulsetic catches degradations minutes before vendors acknowledge them.