September 16, 2026 safety incident: how we responded to a LiteSpeed zero-day attack

Hostinger Blog by 3 min read 362x views
September 16, 2026 safety incident: how we responded to a LiteSpeed zero-day attack

Share Post

Thursday September 17, 2026

Saulius L.

 how we responded to a LiteSpeed zero-day attack

On September 16, 2026, we faced a zero-day assault targeting one of our servers in Brazil.

Our safety squad detected an assault exploiting a earlier undetected exposure in one of our vendors, LiteSpeed Web Server. We worked alongside LiteSpeed to create and deploy a fix, and secured our web hosting surroundings against the exposure the identical day.

This article covers what happened and how we responded.

What happened

On September 16, at 13:08 UTC, our monitoring systems flagged different action on one of our servers in the Brazil data center. The safety squad identified an event inside minutes and began investigating.

They established a sophisticated, targeted assault that, according to its near-continuous action and repeated patterns, appeared to be automated and AI-driven.

The attacker had exploited a zero-day crucial exposure in LiteSpeed Web Server (versions before 6.3.7 Build 2), the application we use to assist websites. The exposure allowed the attacker to acquire root-level admission on one server. In this scenario, a low-privileged person on a shared hosting server could bypass expected isolation boundaries, specified as those provided by CloudLinux CageFS, and append data to records alongside elevated, root-level privileges.

The attacker deployed a webshell on 399 accounts hosted on the affected server; we detected unauthorized commands on 11 of them. We reached out to all of the possibly affected customers individually.

What we did

Following the alert, we impaired external admission to the affected server, suspended the attacker’s accounts, removed malicious scheduled tasks, and preserved evidence for forensic analysis. As a precaution, we additionally impaired an inner tooling integration following observing attacker action against it.

In parallel, we identified the exact exposure and worked immediately alongside LiteSpeed to fix it. By 23:00 UTC on September 16, the patched type (6.3.7 Build 2) was deployed throughout our complete shared hosting fleet.

As part of our event response, we restored affected websites from the most latest backups taken before the assault and migrated them to a new server.

Final notes

Security is a uninterrupted effort, and we obtain it extremely seriously. We acknowledge the changing safety landscape alongside AI-driven attacks and remain committed to protecting our client websites alongside 24/7 monitoring, malware scanning, firewall protection, and uninterrupted exposure checks to safeguard our provision chain.

The figure of researchers operating alongside us through our bug reward program is already growing, and we’re expanding rewards for crucial zero-day vulnerabilities. We’re additionally environment up a dedicated lab alongside the latest AI models to simulate real-world attacks.

We’ll update this article if our ongoing inquiry uncovers any new information.

If you have questions, delight attain out to our assistance squad or email [email protected].

Author

The author

Saulius Lazaravičius

As VP of Product at Hostinger, Saulius oversees Web Hosting Platform & Tools, Managed WordPress, and WebPro Experience. Saulius enjoys observing users through their regular existence activities, looking for problems to solve, and construction products that create users additional productive online, assistance them expend additional period on the things they love, and depart all the remainder for innovation to solve.

Other Article Hostinger Blog
Close Right Ads
Close Left Ads