LiteSpeed cPanel/WHM plugin symlink-following on shared hosting (CVE-2026-54420); exploited ITW; CISA KEV
cve · CVE-2026-54420
Coverage timeline
1
first 2026-06-16 → last 2026-06-16
Briefs
1
1 distinct
Sources cited
7
6 hosts
Sections touched
1
trending_vulns
Co-occurring entities
2
see Related entities below
Story timeline
- 2026-06-16CTI Daily Brief — 2026-06-16
Where this entity is cited
- trending_vulns1
Source distribution
- blog.litespeedtech.com2 (29%)
- cisa.gov1 (14%)
- github.com1 (14%)
- nvd.nist.gov1 (14%)
- socket.dev1 (14%)
- thehackernews.com1 (14%)
Related entities
- Google Threat Intelligence Group AI Threat Tracker (May 2026) — first AI-generated zero-day exploit ITW; AI-augmented malware (CANFAIL, LONGSTREAM, PROMPTFLUX, HONESTCUE); state-actor Gemini abuse (UNC2814, APT45, APT27, UNC5673)
- Shared booking-SaaS breach exposes guests at 100+ Dutch/Belgian/Irish hotels; phishing wave
External references
All cited sources (7)
- blog.litespeedtech.comprimaryfooterLiteSpeed, 2026-06-01https://blog.litespeedtech.com/2026/06/01/security-update-for-litespeed-cpanel-plugin-2/
- blog.litespeedtech.comprimaryinlineLiteSpeed advisoryhttps://blog.litespeedtech.com/2026/05/21/security-update-for-litespeed-cpanel-plugin/
- cisa.govfooterCISA, 2026-06-15https://www.cisa.gov/news-events/alerts/2026/06/15/cisa-adds-two-known-exploited-vulnerabilities-catalog
- github.cominlineGitHub Advisory GHSA-fxrh-cwjh-m33vhttps://github.com/advisories/GHSA-fxrh-cwjh-m33v
- nvd.nist.govinlineNVD CVSS 8.5https://nvd.nist.gov/vuln/detail/CVE-2026-54420
- socket.devinlineSocket, 2026-05-23https://socket.dev/blog/laravel-lang-compromise
- thehackernews.cominlineThe Hacker News, 2026-05-23https://thehackernews.com/2026/05/litespeed-cpanel-plugin-cve-2026-48172.html