CVE-2026-93903: Update LiteSpeed Web Server prior to 6.3.7 build 1

This text was generated using artificial intelligence (AI).CVE-2026-93903 affects LiteSpeed Web Server before 6.3.7 build 1. According to LiteSpeed Technologies, the web server incorrectly handles the validation of internal redirect URLs in a specific edge case. This allows a malicious website user to bypass account isolation, including CageFS.

The vendor provides the fix in LiteSpeed Web Server Enterprise 6.3.7 build 1 . The fix was made available on September 16, 2026; the CVE was documented on September 30, 2026.

Are my systems affected? Check now →