CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

LiteSpeed cPanel Plugin

product · product:litespeed-cpanel-plugin

Coverage
1
first 2026-06-16 → last 2026-09-30
Latest activity
2026-06-16
CVE-2026-54420: LiteSpeed cPanel plugin root escalation on CloudLinux/CageFS shared hosting, exploited in the…
Peak priority
high
1 high
Targets
technology
sectors: technology
Sources cited
3
3 hosts

Action items (1)

Do-now tasks recorded on the entries about LiteSpeed cPanel Plugin, newest first. Check the date before acting on an older one.

  • Patch the LiteSpeed cPanel plugin (CVE-2026-54420) by upgrading to LiteSpeed WHM PlugIn version 5.3.2.1, which bundles cPanel plugin 2.4.8, or uninstall the user-end plugin until then. It is actively exploited on shared CloudLinux/CageFS hosting. Prioritise any public-sector tenant on shared hosting.
    2026-06-16CVE-2026-54420

Defender insights

What each entry about LiteSpeed cPanel Plugin tells a defender to do, newest first.

2026-06-16HIGHexploitedCVE-2026-54420: LiteSpeed cPanel plugin root escalation on CloudLinux/CageFS shared hosting, exploited in the wild (CISA KEV)

Exposure · detection

Story timeline

  1. 2026-06-16CVE-2026-54420: LiteSpeed cPanel plugin root escalation on CloudLinux/CageFS shared hosting, exploited in the wild (CISA KEV)
    trending-vulnerabilities

Hunting pivots

CVEs (exploited first)
Releases covered
LiteSpeed cPanel Plugin
ATT&CK techniques (1 across 1 tactic)

1 technique observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • Privilege EscalationExploitation for Privilege Escalation

Privilege Escalation TA0004

T1068Exploitation for Privilege Escalation×1

Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.

Evidence: 2026-06-16/cve-2026-54420-litespeed-cpanel-whm-plugin-symlink-following · ATT&CK page ↗

Entries about LiteSpeed cPanel Plugin (1)

2026-06-16 · view entry permalink →

HIGHCVE-2026-54420exploitedupdatedNATOA1

The LiteSpeed user-end cPanel plugin before 2.4.8, bundled with the LiteSpeed WHM PlugIn and fixed in WHM PlugIn version 5.3.2.1, lets a user with FTP or web-shell access on a CloudLinux/CageFS shared-hosting server escalate to root. LiteSpeed says its WHM plugin itself was not affected, that the flaw "is being actively exploited", and that it was alerted on 2026-05-31 (LiteSpeed, 2026-06-01). The CVE description attributes the flaw to mishandled symlinks, and The Hacker News lists a CVSS score of 8.5 (The Hacker News, 2026-06-16). CISA added it to the Known Exploited Vulnerabilities catalog on 2026-06-15 (CISA, 2026-06-15).

This vulnerability is being actively exploited, and poses a risk for all user-end plugin versions prior to 2.4.8.

LiteSpeed security update
Correctionrun 2026-09-30T0639Z-auditevidencesourcing_notebodyclassificationtechniquestitleheadlinesummaryactionssourcesaffected_products

The main text above described cross-account file access and cited NVD for exploitation and a CVSS 8.5 score. LiteSpeed states that a user with FTP or web-shell access can escalate to root and that the flaw "is being actively exploited", fixed in cPanel plugin 2.4.8 and WHM plugin 5.3.2.1 (LiteSpeed, 2026-06-01). It says only its user-end cPanel plugin is affected, not its WHM plugin, and gives 2026-05-31 as the date it was alerted rather than a start of exploitation in May. The 8.5 score is now cited to The Hacker News (The Hacker News, 2026-06-16).

vulnerability16 Jun 05:08Zmulti-sourceOpen finding →

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Vulns1

Source distribution

  • blog.litespeedtech.com1 (33%)
  • cisa.gov1 (33%)
  • thehackernews.com1 (33%)