LiteSpeed cPanel Privilege Escalation Flaw Exploited in the Wild (CVE-2026-54420)
ID: eec15d52-0a6e-5612-a146-5368e000b8a6
STIX ID: report--eec15d52-0a6e-5612-a146-5368e000b8a6
Feed Name: securityonline.info
Threat Score
A critical LiteSpeed cPanel plugin privilege-escalation (CVE-2026-54420, CVSS 8.5) is being actively exploited; attackers can use user-supplied symlinks from FTP or web shells on CloudLinux/CageFS to escape tenant isolation and gain root on shared hosting servers. Administrators are urged to upgrade to the patched plugin v2.4.8 (WHM Plugin v5.3.2.1) or remove the user-end plugin as a temporary mitigation, and to hunt cPanel logs for the described fingerprint activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
