What was the issue?
The developers of LiteSpeed Web Server, the software that powers many of our hosting servers, released a critical security advisory. In affected versions, it was possible for a low-privilege website user on a shared server to escalate their access and potentially gain root-level (full administrator) control of the server.
In practical terms, on an unpatched server this could have allowed a malicious user to break out of their own restricted account – bypassing the isolation controls that normally keep accounts separate – and potentially access or alter other websites on the same server.
| Detail | Information |
|---|---|
| Affected software | LiteSpeed Web Server Enterprise, versions before 6.3.7 |
| Type | Privilege escalation (local user to root) |
| Severity | Critical |
| Fixed in | LiteSpeed Web Server Enterprise 6.3.7, hardened further in subsequent builds (latest: 6.3.7 build 2) |
What we have done
As soon as we received the advisory, our team acted. We have:
- 14/09/26 – Updated every server running LiteSpeed – across our shared, reseller and VPS hosting – to version 6.3.7 when the first fix was released.
- 16/09/26 – Applied the follow-up update (6.3.7 build 1) to every one of those servers again as soon as it became available, so they include the additional validation improvement.
- 17/09/26 – Applied the follow-up build the moment it became available, so all servers now run the latest hardened release (6.3.7 build 2 at the time of writing).
- Carried out the recommended post-upgrade checks after each update, including verifying that server-level logging continues to function normally.
Do I need to do anything?
No. Whatever type of hosting you have with us, this has already been taken care of on your behalf and there is nothing for you to do.
Was my website affected?
This was a vulnerability in the server software, not something that required any particular website to be targeted, and we are not sharing that a specific customer site was compromised as a result of it. Updating promptly is a preventative measure. If you have any concerns about your specific account, we are always happy to take a look – just get in touch.