Hostinger says a September 16 attack against one of its Brazil shared-hosting servers exploited a previously unknown vulnerability in LiteSpeed Web Server, prompting an emergency same-day rollout of LiteSpeed Web Server 6.3.7 Build 2 across its shared-hosting fleet.
The company said its monitoring flagged unusual activity at 13:08 UTC and that investigators found an attack path that could bypass CloudLinux CageFS isolation and append data to files with elevated privileges. Hostinger reported that a webshell was deployed on 399 accounts on the affected server, with unauthorized commands detected on 11 accounts.
Hostinger said it disabled external access to the server, suspended the attacker accounts, removed malicious scheduled tasks, preserved forensic evidence, restored affected sites from pre-attack backups, and migrated them to a new server. Customers it considered potentially affected were contacted individually, according to the post.
The disclosure matters beyond Hostinger because LiteSpeed is widely used in shared-hosting stacks, especially for WordPress-heavy providers that pair it with caching and account isolation layers. LiteSpeed Technologies’ release log for version 6.3.7, dated September 17, lists several security hardening changes around lscgid, internal redirect validation, environment variables for .htaccess, and related request handling.
Site operators on LiteSpeed-based hosting should confirm with their provider that LSWS 6.3.7 or an equivalent patched build is in production, review recent file changes and cron jobs, and rotate credentials for accounts that showed unexplained script or webshell activity. For providers, the incident is another reminder that shared-hosting security depends on both server isolation and fast vendor patch distribution.
Sources: Hostinger incident write-up; LiteSpeed Web Server release log.
