All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
14 Sep 2026 - LiteSpeed Enterprise security advisory (URGENT)
Hello,
Got urgent security alert from litespeed about a critical vuln that can potentially allow account user to escape CageFS and get root:
Email attached:
URGENT — Security Advisory
A critical privilege-escalation vulnerability has been identified in LiteSpeed Web Server Enterprise. On shared-hosting servers, a malicious low-privilege website user could potentially gain root-level access to the server.
This could allow an attacker to access or alter other hosted websites and the server itself.
This issue can bypass expected account isolation controls, including CageFS, allowing a malicious website user to potentially escape its restricted environment and gain root-level access to the server.
Affected: LiteSpeed Web Server Enterprise installations prior to v6.3.7
Status: Fix available
Severity: Critical
ACTION REQUIRED (immediately)
We strongly recommend upgrading all affected LiteSpeed Enterprise installations to:
LiteSpeed Web Server Enterprise 6.3.7 or later
The v6.3.7 update includes the following:
[Security] Enhance lscgid request authentication and validation.
[Security] Apply stronger validation of internal redirect URL.
[Security] Block setting of important internal-use environment variables from .htaccess.
[Feature] Enable post-quantum cryptography key exchange.
[Improvement] Add support for the MKCALENDAR request method.
[Bug fix] Address a race condition corner case for ModSecurity engine.
[Bug fix] Address an internal URL cache corner case.
[Bug fix] Improve Node.js process management to avoid lingering idle workers.
[Bug fix] Address HTTP/3 idle connection timeout issue.
[Bug fix] Address a namespace issue for natively configured vhost.
[Bug fix] Address a corner case in SHM locking.
Important Post-Upgrade Note
The stable v6.3.7 release includes an adjustment that permits tightly controlled, root-owned binaries to continue operating safely.
After upgrading, please review your server for unusual CGI activity or piped logging behavior and verify that server-level logging continues to function normally.
Please take action as soon as possible to secure your servers. If you need assistance with the upgrade or have concerns about possible exposure, our support team is ready to help.
Thank you for your immediate attention to this critical security update.

Comments
I don't get why people use LightSpeed and not just Apache.
Because
1. most of them don't know how to optimise their server/website due to lack of technical knowledge.
s/Apache/nginx.
FTFY
On another note, maybe all of the braindead shared hosting vulnerabilities will finally convince some of my consulting clients to switch to proper website stacks instead of idling on this hole-filled crap.
Litespeed gives hosting providers an advantage not because it's faster or better than Apache, but because it's a marketing word. Most people who want web hosting ask for it, and if they do, web hosts will supply it because of demand rather than because it's faster or better than Apache. However, I agree with Litespeed's excellent performance in terms of WordPress acceleration.
~Vikas
I agree, but LightSpeed is designed to be a "replacement" for Apache specifically. That's the only reason I mentioned it.
Are DirectAdmin and cPanel affected?
yes, potentially, a cpanel or directadmin server running litespeed could be affected.