logo

LiteSpeed cPanel Privilege Escalation Flaw Exploited in the Wild (CVE-2026-54420)

ID: eec15d52-0a6e-5612-a146-5368e000b8a6

STIX ID: report--eec15d52-0a6e-5612-a146-5368e000b8a6

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-06-16

Date Updated: 2026-06-16

Author: Do Son

...
...

A critical LiteSpeed cPanel plugin privilege-escalation (CVE-2026-54420, CVSS 8.5) is being actively exploited; attackers can use user-supplied symlinks from FTP or web shells on CloudLinux/CageFS to escape tenant isolation and gain root on shared hosting servers. Administrators are urged to upgrade to the patched plugin v2.4.8 (WHM Plugin v5.3.2.1) or remove the user-end plugin as a temporary mitigation, and to hunt cPanel logs for the described fingerprint activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.