Bleepingcomputer
CISA Issues Urgent Warning on Actively Exploited LiteSpeed cPanel Plugin Vulnerability
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding a critical vulnerability (CVE-2026-54420) in the LiteSpeed cPanel user-end plugin, which allows attackers with FTP or web shell access to escalate privileges to root on shared hosting servers using CloudLinux/CageFS. This vulnerability, reported by Namecheap, is actively being exploited, prompting CISA to mandate that federal agencies secure their systems within three days. The flaw affects all versions prior to 2.4.8 of the plugin, which has been patched in the latest release. Users are advised to run specific commands to check for exploitation and examine system logs for any suspicious activity. The vulnerability was added to CISA's Known Exploited Vulnerabilities Catalog on June 15, 2026, following its public disclosure on June 14, 2026. This situation highlights the ongoing risks associated with privilege escalation vulnerabilities in widely used software.
Key Points: • CISA warns of an actively exploited vulnerability in LiteSpeed cPanel plugin (CVE-2026-54420). • The flaw allows privilege escalation to root for attackers with FTP or web shell access. • Federal agencies must secure their systems within three days as per CISA's directive.