CISA Issues Urgent Warning on Actively Exploited LiteSpeed cPanel Plugin Vulnerability

CISA Issues Urgent Warning on Actively Exploited LiteSpeed cPanel Plugin Vulnerability

First seen 16 Jun 2026, 11:21 UTC CybersecuritynewsFeeds.4SysopsBleepingcomputerblog.litespeedtech.com 83% similarity 72.9

Article Content

Browse articles
ThreatCluster

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding a critical vulnerability (CVE-2026-54420) in the LiteSpeed cPanel user-end plugin, which allows attackers with FTP or web shell access to escalate privileges to root on shared hosting servers using CloudLinux/CageFS. This vulnerability, reported by Namecheap, is actively being exploited, prompting CISA to mandate that federal agencies secure their systems within three days. The flaw affects all versions prior to 2.4.8 of the plugin, which has been patched in the latest release. Users are advised to run specific commands to check for exploitation and examine system logs for any suspicious activity. The vulnerability was added to CISA's Known Exploited Vulnerabilities Catalog on June 15, 2026, following its public disclosure on June 14, 2026. This situation highlights the ongoing risks associated with privilege escalation vulnerabilities in widely used software.

Key Points: • CISA warns of an actively exploited vulnerability in LiteSpeed cPanel plugin (CVE-2026-54420). • The flaw allows privilege escalation to root for attackers with FTP or web shell access. • Federal agencies must secure their systems within three days as per CISA's directive.

ThreatCluster AI How this analysis works

Timeline

2026-05-21
CVE-2026-48172 published
A vulnerability in LiteSpeed cPanel was disclosed, allowing unauthenticated script execution.
Bleepingcomputer
2026-05-26
CVE-2026-48172 added to CISA KEV
CISA included CVE-2026-48172 in its Known Exploited Vulnerabilities Catalog due to active exploitation.
Bleepingcomputer
2026-06-14
CVE-2026-54420 published
LiteSpeed disclosed a critical vulnerability in its cPanel plugin, affecting versions prior to 2.4.8.
blog.litespeedtech.com
2026-06-15
CVE-2026-54420 added to CISA KEV
CISA added CVE-2026-54420 to its Known Exploited Vulnerabilities Catalog due to ongoing exploitation.
Bleepingcomputer
2026-06-16
CISA issues urgent warning
CISA mandates federal agencies to secure systems against CVE-2026-54420 within three days.
Bleepingcomputer

Community

Browse all →