ctipilot.ch

LiteSpeed cPanel/WHM plugin symlink-following on CloudLinux/CageFS shared hosting; exploited ITW May 2026; CISA KEV

cve · CVE-2026-54420

Coverage timeline
2
first 2026-06-16 → last 2026-06-22
Peak priority
high
1 high · 1 notable
Sources cited
3
3 hosts
Sections touched
2
trending-vulnerabilities, weekly-vuln-rollup
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
0
no mapped behavior yet

Story timeline

  1. 2026-06-22CVE-2026-54420 — LiteSpeed cPanel/WHM plugin: symlink-following on shared hosting, exploited (CISA KEV)
    weekly-vuln-rollup
  2. 2026-06-16CVE-2026-54420 — LiteSpeed cPanel/WHM plugin: symlink-following on shared hosting, exploited in the wild (CISA KEV)
    trending-vulnerabilities

Where this entity is cited

  • trending-vulnerabilities1
  • weekly-vuln-rollup1

Source distribution

  • blog.litespeedtech.com1 (33%)
  • cisa.gov1 (33%)
  • nvd.nist.gov1 (33%)

explore in graph

Entries about LiteSpeed cPanel/WHM plugin symlink-following on CloudLinux/CageFS shared hosting; exploited ITW May 2026; CISA KEV (2)

2026-06-22 · view entry permalink →

NOTABLECVE-2026-54420exploited

The LiteSpeed cPanel plugin before 2.4.8 mishandles user-supplied symlinks on CloudLinux/CageFS shared hosting, letting a user with FTP or web-shell access escalate; it is exploited in the wild and KEV-listed (LiteSpeed; daily 06-16). Relevant to any public-sector or education entity running shared cPanel hosting. Update to the LiteSpeed WHM PlugIn version 5.3.2.1.

The LiteSpeed cPanel plugin before 2.4.8 mishandles user-supplied symlinks on CloudLinux/CageFS shared hosting, letting a user with FTP or web-shell access escalate; it is exploited in the wild and KEV-listed (LiteSpeed; daily 06-16).

ctipilot v2 brief (migrated)
vulnerability22 Jun 00:14Zmulti-sourceOpen finding ↗

2026-06-16 · view entry permalink →

HIGHCVE-2026-54420exploited

The LiteSpeed cPanel plugin before 2.4.8 (fixed in the LiteSpeed WHM PlugIn version 5.3.2.1) mishandles symlinks supplied by a user with FTP or web-shell access on a CloudLinux/CageFS shared-hosting server, enabling cross-account file access and privilege escalation; NVD records exploitation in the wild in May 2026 (NVD CVSS 8.5). CISA added it to the Known Exploited Vulnerabilities catalog on 2026-06-15 (CISA, 2026-06-15). The exposure is most acute for hosting providers and any public-sector tenant on shared CloudLinux infrastructure. Patch to WHM PlugIn 5.3.2.1 / cPanel plugin 2.4.8.

The LiteSpeed cPanel plugin before 2.4.8 (fixed in the LiteSpeed WHM PlugIn version 5.3.2.1) mishandles symlinks supplied by a user with FTP or web-shell access on a CloudLinux/CageFS shared-hosting server, enabling cross-account file access and privilege escalation; NVD records exploitation in the …

ctipilot v2 brief (migrated)
vulnerability16 Jun 05:08Zmulti-sourceOpen finding ↗