Back Feeds.4Sysops CISA warns of LiteSpeed cPanel plugin flaw allowing root access
A critical privilege escalation vulnerability in the LiteSpeed cPanel plugin is now being exploited in the wild, prompting a warning from CISA. The flaw, tracked as CVE-2026-54420, allows attackers with basic FTP or web shell access to gain full root privileges on shared hosting environments. This security hole specifically affects servers running CloudLinux or CageFS due to the improper handling of user-provided symlinks. Source
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
