logo

CISA Issues Urgent Warning on Actively Exploited LiteSpeed cPanel Plugin Vulnerability

ID: ae2c60c3-cd38-5368-b2a7-dc913765cc30

STIX ID: report--ae2c60c3-cd38-5368-b2a7-dc913765cc30

Feed Name: ThreatCluster

Threat Score
85/100

Date Published: 2026-06-16

Date Updated: 2026-06-22

...
...

The U.S. CISA warned of CVE-2026-54420, a critical privilege-escalation flaw in the LiteSpeed cPanel plugin allowing attackers with FTP or web-shell access to obtain root on shared hosting (CloudLinux/CageFS). The vulnerability is being actively exploited, was added to CISA's Known Exploited Vulnerabilities Catalog, and federal agencies were ordered to remediate within three days; vendor patches (2.4.8+) and forensic checks are recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.