1. Home
  2. Website Security
  3. Security Notices
  4. Security advisory: LiteSpeed Web Server update (action already taken by PAC)

Security advisory: LiteSpeed Web Server update (action already taken by PAC)

No action is needed from you. A critical security issue was identified in LiteSpeed Web Server Enterprise, and LiteSpeed has since released several rapid follow-up updates to further harden it. We have applied every one of these as they were released, and all of our servers running LiteSpeed are now on the latest available version. We are sharing this in the interest of transparency so you know what happened and what we did about it.

What was the issue?

The developers of LiteSpeed Web Server, the software that powers many of our hosting servers, released a critical security advisory. In affected versions, it was possible for a low-privilege website user on a shared server to escalate their access and potentially gain root-level (full administrator) control of the server.

In practical terms, on an unpatched server this could have allowed a malicious user to break out of their own restricted account – bypassing the isolation controls that normally keep accounts separate – and potentially access or alter other websites on the same server.

Detail Information
Affected software LiteSpeed Web Server Enterprise, versions before 6.3.7
Type Privilege escalation (local user to root)
Severity Critical
Fixed in LiteSpeed Web Server Enterprise 6.3.7, hardened further in subsequent builds (latest: 6.3.7 build 2)

What we have done

As soon as we received the advisory, our team acted. We have:

  • 14/09/26 – Updated every server running LiteSpeed – across our shared, reseller and VPS hosting – to version 6.3.7 when the first fix was released.
  • 16/09/26 – Applied the follow-up update (6.3.7 build 1) to every one of those servers again as soon as it became available, so they include the additional validation improvement.
  • 17/09/26 – Applied the follow-up build the moment it became available, so all servers now run the latest hardened release (6.3.7 build 2 at the time of writing).
  • Carried out the recommended post-upgrade checks after each update, including verifying that server-level logging continues to function normally.

The fixed release (6.3.7) also strengthens request authentication and validation, tightens how internal redirects and environment variables are handled, and includes a number of stability and performance improvements. In other words, alongside closing the security hole it makes the platform more robust.

Do I need to do anything?

No. Whatever type of hosting you have with us, this has already been taken care of on your behalf and there is nothing for you to do.

Was my website affected?

This was a vulnerability in the server software, not something that required any particular website to be targeted, and we are not sharing that a specific customer site was compromised as a result of it. Updating promptly is a preventative measure. If you have any concerns about your specific account, we are always happy to take a look – just get in touch.

Questions about this advisory or your server? Please contact our support team and we will be glad to help. Keeping your hosting secure and up to date is part of what we do, and we would always rather you asked than wondered.

Updated on October 1, 2026
Was this article helpful?

Related Articles

Need Support?
Can't find the answer you're looking for? Don't worry we're here to help!
GET SOME HELP!