High severity8.5CISA KEVNVD Advisory· Published Jun 14, 2026· Updated Jun 16, 2026
CVE-2026-54420
CVE-2026-54420
Description
LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS, as exploited in the wild in May 2026.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: <5.3.2.0
- Range: <2.4.8
Patches
Vulnerability mechanics
References
3- blog.litespeedtech.com/2026/06/01/security-update-for-litespeed-cpanel-plugin-2/nvdVendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
- www.litespeedtech.com/products/litespeed-web-server/control-panel-support/cpanelnvdProduct
News mentions
7- ⚡ Weekly Recap: Browser Bugs, EDR Killers, TV Botnet, OpenBSD Flaw, Android Trojan, and MoreThe Hacker News · Jun 22, 2026
- CISA Adds LiteSpeed cPanel Plugin Vulnerability to KEV List Following Active ExploitationCyber Security News · Jun 19, 2026
- Joomla, LiteSpeed Vulnerabilities Exploited in AttacksSecurityWeek · Jun 17, 2026
- CISA warns of another cPanel plugin flaw exploited in attacksBleepingComputer · Jun 16, 2026
- LiteSpeed cPanel Plugin 0-Day Vulnerability Actively Exploited in the WildCyber Security News · Jun 16, 2026
- CISA Flags LiteSpeed cPanel Plugin Flaw Exploited for Root Privilege EscalationThe Hacker News · Jun 16, 2026
- CISA Adds Two Known Exploited Vulnerabilities to CatalogCISA Alerts