logo

CISA Flags LiteSpeed cPanel Plugin Flaw Exploited for Root Privilege Escalation

ID: 52cb6567-e9de-5766-bab7-3cc9e68629f8

STIX ID: report--52cb6567-e9de-5766-bab7-3cc9e68629f8

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2026-06-16

Date Updated: 2026-06-16

Author: [email protected] (The Hacker News)

...
...

CISA added CVE-2026-54420 (CVSS 8.5) to its Known Exploited Vulnerabilities catalog; the flaw in LiteSpeed's cPanel/WHM plugin allows an attacker with FTP or web-shell access to escalate privileges to root on shared hosting (CloudLinux/CageFS). LiteSpeed published a grep-based detection command and behavioral indicators (chained generateEcCert→packageUserSize and high concurrent calls) and urges users to upgrade to LiteSpeed WHM Plugin v5.3.2.1 / cPanel plugin v2.4.8 or later to mitigate the issue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.