CVE-2026-93903
LiteSpeed Web Server (LSWS) before 6.3.7 build 1 mishandles internal redirect URL validation in a certain "corner case."
- Published Sep 30, 2026
- CVSS 9.4 critical
- 0.3% chance of exploitation in the next 30 days (EPSS)
- A fix is available