All accessible Fully Managed and Core Managed servers running outdated versions of LiteSpeed have been successfully updated to the patched version, 6.3.7. Services have remained operational, and no additional issues have been identified during monitoring.
All accessible Fully and Core-Managed servers running outdated versions of LiteSpeed have been patched to version 6.3.7. The same webserver service that was in use before the LiteSpeed upgrade remains in use afterwards.
WebPros (cPanel) posted news regarding a critical privilege-escalation vulnerability within the LiteSpeed software. A malicious website user could potentially gain root-level access to the server (even bypassing account isolation controls such as CageFS).
We will attempt to update LiteSpeed to the patched version (6.3.7) where we are able to via Automation. Regardless, please ensure your Litespeed is up-to-date.