2026-06-16HIGHexploitedCVE-2026-54420: LiteSpeed cPanel plugin root escalation on CloudLinux/CageFS shared hosting, exploited in the wild (CISA KEV)
LiteSpeed cPanel Plugin
product · product:litespeed-cpanel-plugin
Coverage
1
first 2026-06-16 → last 2026-09-30
Latest activity
2026-06-16
CVE-2026-54420: LiteSpeed cPanel plugin root escalation on CloudLinux/CageFS shared hosting, exploited in the…
Peak priority
high
1 high
Targets
technology
sectors: technology
Sources cited
3
3 hosts
Action items (1)
Do-now tasks recorded on the entries about LiteSpeed cPanel Plugin, newest first. Check the date before acting on an older one.
- Patch the LiteSpeed cPanel plugin (CVE-2026-54420) by upgrading to LiteSpeed WHM PlugIn version 5.3.2.1, which bundles cPanel plugin 2.4.8, or uninstall the user-end plugin until then. It is actively exploited on shared CloudLinux/CageFS hosting. Prioritise any public-sector tenant on shared hosting.2026-06-16CVE-2026-54420
Defender insights
What each entry about LiteSpeed cPanel Plugin tells a defender to do, newest first.
Exposure · detection
Story timeline
Hunting pivots
CVEs (exploited first)
Releases covered
LiteSpeed cPanel Plugin
ATT&CK techniques (1 across 1 tactic)
1 technique observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Privilege EscalationExploitation for Privilege Escalation
Privilege Escalation TA0004
T1068Exploitation for Privilege Escalation×1
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.
Evidence: 2026-06-16/cve-2026-54420-litespeed-cpanel-whm-plugin-symlink-following · ATT&CK page ↗
Entries about LiteSpeed cPanel Plugin (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
Where this entity is cited
Source distribution
- blog.litespeedtech.com1 (33%)
- cisa.gov1 (33%)
- thehackernews.com1 (33%)
All cited sources (3)
- blog.litespeedtech.comLiteSpeed security updatehttps://blog.litespeedtech.com/2026/06/01/security-update-for-litespeed-cpanel-plugin-2/
- cisa.govCISA KEV alerthttps://www.cisa.gov/news-events/alerts/2026/06/15/cisa-adds-two-known-exploited-vulnerabilities-catalog
- thehackernews.comThe Hacker Newshttps://thehackernews.com/2026/06/cisa-flags-litespeed-cpanel-plugin-flaw.html