logo

CISA Warns of Another Actively Exploited cPanel Plugin Flaw

ID: b31bc130-f233-5cbd-a973-591f91fb4959

STIX ID: report--b31bc130-f233-5cbd-a973-591f91fb4959

Feed Name: CosmicBytez Labs

Threat Score
85/100

Date Published: 2026-06-16

Date Updated: 2026-06-17

...
...

CISA has added CVE-2026-54420 — a missing-authentication flaw in the LiteSpeed cPanel user-end plugin that enables elevated command/script execution — to its Known Exploited Vulnerabilities list and issued a three-day federal patching directive; the vulnerability is actively exploited in the wild and poses high risk to multi-tenant hosting environments, prompting immediate patching, disabling the plugin if unpatched, and monitoring for compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.