← Back to Vulnerability Reports CVE Intelligence

CVE-2026-54420

LiteSpeed CPanel PluginHIGH · CVSS 8.5 In the wild In CISA KEV

What is CVE-2026-54420?

LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS, as exploited in the wild in May 2026.

CVSS8.5 NVD 3.1
SeverityHIGH
Exploitation In the wild In CISA KEV
EPSS1% · P45
Triage statusActive Exploit
ActionPatch immediately
CVSS vectorCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
CWECWE-61
NVD published2026-06-14
NVD last modified2026-06-16

CISA Known Exploited Vulnerability

LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability

Added to KEV2026-06-15
Federal patch deadline2026-06-18
Known ransomware useUnknown

Affected product

LiteSpeed CPanel Plugin

NVD also lists CPE entries for: Litespeedtech Litespeed Cpanel Plugin, Litespeedtech Litespeed Whm Plugin

Remediation Steps

  1. Apply the patch for the LiteSpeed cPanel user-end plugin to all cPanel servers
  2. Test patched plugin functionality in a staging environment before production deployment
  3. Review server logs for evidence of exploitation attempts
  4. Notify hosting customers of patch deployment timeline

Coverage on defend.network

🤖 This CVE page is generated by defend.network from NVD, CISA KEV, EPSS, and our verified daily briefings. Severity and exploitation data come from official sources; always verify remediation steps against the official vendor advisory before acting in production.

Get Critical CVE Alerts

Subscribe free and hear about actively exploited CVEs like this one first.