All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
(Another) 16 Sep 2026 - LiteSpeed Enterprise security advisory (URGENT)
As I posted a few days ago [https://lowendtalk.com/discussion/221122/14-sep-2026-litespeed-enterprise-security-advisory-urgent], LiteSpeed just released another security update.
This is an additional fix for internal redirect URL validation. Original issue could allow a malicious website user to bypass account isolation, including CageFS.
If you already patched yesterday, update again to latest LiteSpeed Enterprise (6.3.7 build 1).
Email attached:
URGENT — Security Advisory
Following yesterday’s security advisory, LiteSpeed has released an additional update addressing another corner case in internal redirect URL validation.
Because the original vulnerability could allow a malicious website user to bypass expected account-isolation controls, including CageFS, we strongly recommend that all customers update again to the latest available LiteSpeed Web Server Enterprise release.
Affected: LiteSpeed Web Server Enterprise installations not running the latest available release
Status: Additional security fix available
Action required: Update immediately
ACTION REQUIRED (immediately)
Please upgrade LiteSpeed Web Server Enterprise to the latest available version.
This update (v6.3.7 build 1) includes the following additional security fix:
[Security] Address another corner case in internal redirect URL validation.
Even if you updated following yesterday’s advisory, please apply this latest update to ensure your server includes the additional validation improvement.
After upgrading, please review your server for unusual CGI activity or piped logging behavior and verify that server-level logging continues to function normally.
If you need assistance with the upgrade or have concerns about possible exposure, our support team is ready to help.
Thank you for your immediate attention to this security update.
LiteSpeed Team

Comments
instruction unclear. cog stuck in chicen farm and can't be pulled
also is this vuln only affect the enterprise version? where's the official announcement/release link?
lol
They only sent an email, no official link.
LMAO
Another one today:
Announcing:
LiteSpeed Web Server v6.3.7 Build 2
CHANGE LOG:
[Security] Further lock down lscgid.
Update to the latest build:
/usr/local/lsws/admin/misc/lsup.sh -f -v 6.3.7
Check the currently installed build number:
cat lsws/BUILD
I mentioned in the other thread, I think they are not releasing the fixes for OLS and only enterprise due to that making the vulnerabilities public if open source one is patched. Of course I may be wrong and I apologize if so, but I already removed OpenLiteSpeed from all of my environments. The LS team didn’t reply to my ticket from 2 days ago asking if OLS was vulnerable.
a 3rd update has been released 1 hour ago