π¨ ACTIVE EXPLOITS & INCIDENTS
- LiteSpeed cPanel Plugin CVE-2026-48172 Exploited to Run Scripts as Root β The Hacker News A critical privilege escalation vulnerability (CVSS 10.0) in LiteSpeed User-End cPanel Plugin is actively exploited in the wild. CVE-2026-48172 allows any cPanel user, including attackers or compromised accounts, to execute arbitrary scripts as root by abusing incorrect privilege assignment. Immediate patching or mitigation is essential to prevent full system compromise on affected hosting environments.
π VULNERABILITIES & CVEs
- Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV β The Hacker News CVE-2026-9082, a critical SQL injection vulnerability (CVSS 6.5) impacting all supported Drupal Core versions, is confirmed exploited in the wild and now listed in CISAβs Known Exploited Vulnerabilities catalog. Attackers can leverage this flaw to execute arbitrary SQL commands, potentially leading to data leakage or site takeover. Urgent patching of Drupal Core is strongly advised for all affected deployments.