CISA warned that attackers are actively exploiting another flaw in LiteSpeed’s cPanel user-end plugin and told U.S. federal agencies to secure affected servers within three days. The bug, CVE-2026-54420, affects LiteSpeed cPanel user-end plugin versions before 2.4.8 and can let an attacker who already has FTP access or a web shell (a malicious script that gives remote server control) escalate privileges to root on shared hosting servers running CloudLinux/CageFS; LiteSpeed said exploitation has been seen in the wild and provided log-based detection guidance.
Why it matters: Organizations using affected LiteSpeed cPanel hosting plugins should treat this as urgent because active attackers can turn limited server access into full root control. Update to version 2.4.8 or later immediately and check logs for signs of exploitation.
Ionut Arghire
2026.06.17
89% relevant
This article adds exploitation context and remediation details for the same LiteSpeed event, including that exploitation has occurred since May, the bug affects user-end cPanel plugin versions before 2.4.8, and attackers with FTP or web-shell access can escalate to root on CloudLinux/CageFS shared hosting servers.
Sergiu Gatlan
2026.06.16
100% relevant
This article establishes a distinct tracked event centered on CVE-2026-54420, a separate actively exploited LiteSpeed cPanel plugin flaw from the previously tracked LiteSpeed cPanel plugin zero-day CVE-2026-48172.
← Back to all stories