CVE-2026-54420

HIGH CISA KEV EPSS 66.0%
Published Jun 14, 20262w ago · Modified Jun 17, 20261w ago
8.5 CVSS 3.1
High
Find Similar
Published Jun 14, 2026 2w ago
Last Modified Jun 17, 2026 1w ago
KEV Listed Jun 15, 2026 2w ago
KEV Due Jun 18, 2026 11d overdue

Description

LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS, as exploited in the wild in May 2026.

CVSS Details

Base Score
8.5
Exploitability
1.8
Impact
6.0
Vector string
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Attack Vector Network
Attack Complexity High
Privileges Required Low
User Interaction None
Scope Changed
Confidentiality High
Integrity High
Availability High

Threat Intelligence

CISA Known Exploited Overdue 11d
Added
Jun 15, 2026
Due
Jun 18, 2026

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

EPSS Exploit Probability
66.0% percentile
Exploit & Patch Status
Actively Exploited (KEV)
No Patch Available

Weaknesses 1

CWE-61

Affected Products 2

VendorProductVersionRange
litespeedtechlitespeed_cpanel_plugin* <2.4.8
litespeedtechlitespeed_whm_plugin* <5.3.2.0

References 3

  • blog.litespeedtech.com https://blog.litespeedtech.com/2026/06/01/security-update-for-litespeed-cpanel-plugin-2/
    Vendor Advisory
  • cisa.gov https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-54420
    US Government Resource
  • litespeedtech.com https://www.litespeedtech.com/products/litespeed-web-server/control-panel-support/cpanel
    Product

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.