logo

CISA Adds LiteSpeed cPanel Plugin Vulnerability to KEV List Following Active Exploitation

ID: 10b4d031-9421-57be-8e62-c795f74695e4

STIX ID: report--10b4d031-9421-57be-8e62-c795f74695e4

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-06-19

Date Updated: 2026-06-20

Author: Abinaya

...
...

CISA added CVE-2026-54420 — a LiteSpeed cPanel plugin symbolic link (symlink) handling vulnerability — to its Known Exploited Vulnerabilities catalog after evidence of active exploitation; the flaw can allow attackers with limited access (e.g., FTP credentials or web shells) to access sensitive files outside jailed directories in multi-tenant hosting, potentially enabling privilege escalation or data exposure. Organizations are urged to apply vendor mitigations, enforce secure file permissions, disable unsafe symlink behavior, monitor for suspicious access, and comply with BOD 26-04 remediation deadlines.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.