CISA Warns of Another Actively Exploited cPanel Plugin Flaw
ID: b31bc130-f233-5cbd-a973-591f91fb4959
STIX ID: report--b31bc130-f233-5cbd-a973-591f91fb4959
Feed Name: CosmicBytez Labs
Threat Score
CISA has added CVE-2026-54420 — a missing-authentication flaw in the LiteSpeed cPanel user-end plugin that enables elevated command/script execution — to its Known Exploited Vulnerabilities list and issued a three-day federal patching directive; the vulnerability is actively exploited in the wild and poses high risk to multi-tenant hosting environments, prompting immediate patching, disabling the plugin if unpatched, and monitoring for compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
