Liquid Web experienced a minor incident on September 14, 2026 affecting CPanel, lasting 17h 17m. The incident has been resolved; the full update timeline is below.
Affected components
Update timeline
- investigating Sep 14, 2026, 08:31 PM UTC
WebPros (cPanel) posted news regarding a critical privilege-escalation vulnerability within the LiteSpeed software. A malicious website user could potentially gain root-level access to the server (even bypassing account isolation controls such as CageFS). More Information can be found here: https://support.cpanel.net/hc/en-us/articles/43483286674583-Security-LiteSpeed-Enterprise-security-advisory-September-14-2026 We will attempt to update LiteSpeed to the patched version (6.3.7) where we are able to via Automation. Regardless, please ensure your Litespeed is up-to-date. If you have any questions or concerns, please contact [email protected]
- monitoring Sep 15, 2026, 04:19 AM UTC
All accessible Fully and Core-Managed servers running outdated versions of LiteSpeed have been patched to version 6.3.7. The same webserver service that was in use before the LiteSpeed upgrade remains in use afterwards. If you have any questions or concerns, please contact [email protected].
- resolved Sep 15, 2026, 01:49 PM UTC
All accessible Fully Managed and Core Managed servers running outdated versions of LiteSpeed have been successfully updated to the patched version, 6.3.7. Services have remained operational, and no additional issues have been identified during monitoring. This incident is now resolved. If you have any questions or concerns, please contact [email protected].