Use cases
Software Products E-commerce MSPs Schools Development & Marketing DevOps Agencies Help Desk
Company
Internet Status Blog Pricing Log in Get started free

Outage in Liquid Web

LiteSpeed security advisory

Resolved Minor
September 14, 2026 - Started about 19 hours ago - Lasted about 17 hours
Official incident page

Incident Report

Summary AI Generated

A critical privilege-escalation vulnerability was discovered in LiteSpeed software, allowing malicious users to potentially gain root-level server access and bypass account isolation controls like CageFS. Liquid Web patched all accessible Fully Managed and Core Managed servers running outdated LiteSpeed versions, updating them to the secured version 6.3.7. The incident was resolved after approximately 17 hours with services remaining operational throughout and no additional issues identified.

WebPros (cPanel) posted news regarding a critical privilege-escalation vulnerability within the LiteSpeed software. A malicious website user could potentially gain root-level access to the server (even bypassing account isolation controls such as CageFS). More Information can be found here: https://support.cpanel.net/hc/en-us/articles/43483286674583-Security-LiteSpeed-Enterprise-security-advisory-September-14-2026 We will attempt to update LiteSpeed to the patched version (6.3.7) where we are able to via Automation. Regardless, please ensure your Litespeed is up-to-date. If you have any questions or concerns, please contact support@liquidweb.com

Trusted by 1,000+ teams

The Status Page Aggregator with Early Outage Detection

Stop finding out about outages from your users. Monitor 6,320+ cloud services and get alerted the second something breaks.

IsDown status aggregator dashboard
Latest Updates ( sorted recent to last )
RESOLVED about 2 hours ago - at 09/15/2026 01:49PM

All accessible Fully Managed and Core Managed servers running outdated versions of LiteSpeed have been successfully updated to the patched version, 6.3.7. Services have remained operational, and no additional issues have been identified during monitoring.

This incident is now resolved.

If you have any questions or concerns, please contact support@liquidweb.com.

MONITORING about 12 hours ago - at 09/15/2026 04:19AM

All accessible Fully and Core-Managed servers running outdated versions of LiteSpeed have been patched to version 6.3.7. The same webserver service that was in use before the LiteSpeed upgrade remains in use afterwards.

If you have any questions or concerns, please contact support@liquidweb.com.

INVESTIGATING about 19 hours ago - at 09/14/2026 08:31PM

WebPros (cPanel) posted news regarding a critical privilege-escalation vulnerability within the LiteSpeed software. A malicious website user could potentially gain root-level access to the server (even bypassing account isolation controls such as CageFS).

More Information can be found here:
https://support.cpanel.net/hc/en-us/articles/43483286674583-Security-LiteSpeed-Enterprise-security-advisory-September-14-2026

We will attempt to update LiteSpeed to the patched version (6.3.7) where we are able to via Automation. Regardless, please ensure your Litespeed is up-to-date.

If you have any questions or concerns, please contact support@liquidweb.com

The Status Page Aggregator with Early Outage Detection

With IsDown, you can monitor all your critical services' official status pages from one centralized dashboard and receive instant alerts the moment an outage is detected. Say goodbye to constantly checking multiple sites for updates and stay ahead of outages with IsDown.

Start free trial

No credit card required · Cancel anytime · 6320 services available

Integrations with Slack Microsoft Teams Google Chat Datadog PagerDuty Zapier Discord Webhook