CISA Flags LiteSpeed cPanel Plugin Flaw Exploited for Root Privilege Escalation
ID: 52cb6567-e9de-5766-bab7-3cc9e68629f8
STIX ID: report--52cb6567-e9de-5766-bab7-3cc9e68629f8
Feed Name: The Hacker News
CISA added CVE-2026-54420 (CVSS 8.5) to its Known Exploited Vulnerabilities catalog; the flaw in LiteSpeed's cPanel/WHM plugin allows an attacker with FTP or web-shell access to escalate privileges to root on shared hosting (CloudLinux/CageFS). LiteSpeed published a grep-based detection command and behavioral indicators (chained generateEcCert→packageUserSize and high concurrent calls) and urges users to upgrade to LiteSpeed WHM Plugin v5.3.2.1 / cPanel plugin v2.4.8 or later to mitigate the issue.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
