CISA Issues Urgent Warning on Actively Exploited LiteSpeed cPanel Plugin Vulnerability
ID: ae2c60c3-cd38-5368-b2a7-dc913765cc30
STIX ID: report--ae2c60c3-cd38-5368-b2a7-dc913765cc30
Feed Name: ThreatCluster
Threat Score
The U.S. CISA warned of CVE-2026-54420, a critical privilege-escalation flaw in the LiteSpeed cPanel plugin allowing attackers with FTP or web-shell access to obtain root on shared hosting (CloudLinux/CageFS). The vulnerability is being actively exploited, was added to CISA's Known Exploited Vulnerabilities Catalog, and federal agencies were ordered to remediate within three days; vendor patches (2.4.8+) and forensic checks are recommended.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
