September 16, 2026 security incident: how we responded to a LiteSpeed zero-day attack

September 16, 2026 security incident: how we responded to a LiteSpeed zero-day attack

On September 16, 2026, we faced a zero-day attack targeting one of our servers in Brazil.

Our security team detected an attack exploiting a previously undetected vulnerability in one of our vendors, LiteSpeed Web Server. We worked with LiteSpeed to develop and deploy a fix, and secured our web hosting environment against the vulnerability the same day.

This post covers what happened and how we responded.

What happened

On September 16, at 13:08 UTC, our monitoring systems flagged unusual activity on one of our servers in the Brazil data center. The security team identified an incident within minutes and began investigating.

They found a sophisticated, targeted attack that, based on its near-continuous activity and repeated patterns, appeared to be automated and AI-driven.

The attacker had exploited a zero-day critical vulnerability in LiteSpeed Web Server (versions before 6.3.7 Build 2), the software we use to serve websites. The vulnerability allowed the attacker to gain root-level access on one server. In this scenario, a low-privileged user on a shared hosting server could bypass expected isolation boundaries, such as those provided by CloudLinux CageFS, and append data to files with elevated, root-level privileges.

The attacker deployed a webshell on 399 accounts hosted on the affected server; we detected unauthorized commands on 11 of them. We reached out to all of the potentially affected customers individually.

What we did

Following the alert, we disabled external access to the affected server, suspended the attacker’s accounts, removed malicious scheduled tasks, and preserved evidence for forensic analysis. As a precaution, we also disabled an internal tooling integration after observing attacker activity against it.

In parallel, we identified the exact vulnerability and worked directly with LiteSpeed to fix it. By 23:00 UTC on September 16, the patched version (6.3.7 Build 2) was deployed across our entire shared hosting fleet.

As part of our incident response, we restored affected websites from the most recent backups taken before the attack and migrated them to a new server.

Final notes

Security is a continuous effort, and we take it very seriously. We acknowledge the changing security landscape with AI-driven attacks and remain committed to protecting our client websites with 24/7 monitoring, malware scanning, firewall protection, and continuous vulnerability checks to safeguard our supply chain.

The number of researchers working with us through our bug reward program is already growing, and we’re increasing rewards for critical zero-day vulnerabilities. We’re also setting up a dedicated lab with the latest AI models to simulate real-world attacks.

We’ll update this post if our ongoing investigation uncovers any new information.

If you have questions, please reach out to our support team or email security@hostinger.com.

Author
The author

Saulius Lazaravičius

As VP of Product at Hostinger, Saulius oversees Web Hosting Platform & Tools, Managed WordPress, and WebPro Experience. Saulius enjoys observing users through their daily life activities, looking for problems to solve, and building products that make users more efficient online, help them spend more time on the things they love, and leave all the rest for technology to solve.