High severity8.5CISA KEVNVD Advisory· Published Jun 14, 2026· Updated Jun 16, 2026
CVE-2026-54420
CVE-2026-54420
Description
LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS, as exploited in the wild in May 2026.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- Range: <2.4.8
- cpe:2.3:a:litespeedtech:litespeed_cpanel_plugin:*:*:*:*:*:*:*:*Range: <2.4.8
cpe:2.3:a:litespeedtech:litespeed_whm_plugin:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:litespeedtech:litespeed_whm_plugin:*:*:*:*:*:*:*:*range: <5.3.2.0
- (no CPE)range: <5.3.2.0
Patches
Vulnerability mechanics
References
3- blog.litespeedtech.com/2026/06/01/security-update-for-litespeed-cpanel-plugin-2/nvdVendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
- www.litespeedtech.com/products/litespeed-web-server/control-panel-support/cpanelnvdProduct
News mentions
8- Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole ServerThe Hacker News · Aug 28, 2026
- ⚡ Weekly Recap: Browser Bugs, EDR Killers, TV Botnet, OpenBSD Flaw, Android Trojan, and MoreThe Hacker News · Jun 22, 2026
- CISA Adds LiteSpeed cPanel Plugin Vulnerability to KEV List Following Active ExploitationCyber Security News · Jun 19, 2026
- Joomla, LiteSpeed Vulnerabilities Exploited in AttacksSecurityWeek · Jun 17, 2026
- CISA warns of another cPanel plugin flaw exploited in attacksBleepingComputer · Jun 16, 2026
- LiteSpeed cPanel Plugin 0-Day Vulnerability Actively Exploited in the WildCyber Security News · Jun 16, 2026
- CISA Flags LiteSpeed cPanel Plugin Flaw Exploited for Root Privilege EscalationThe Hacker News · Jun 16, 2026
- CISA Adds Two Known Exploited Vulnerabilities to CatalogCISA Alerts