VulnerabilityBleeping Computer
9.8 — CRITICAL
CISA warns of another cPanel plugin flaw exploited in attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has given U.S. government agencies three days to secure their servers against an actively exploited vulnerability (CVE-2026-54420) in the LiteSpeed cPanel user-end plugin. [...]
🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview
A high-severity vulnerability (CVE-2026-54420) in the LiteSpeed cPanel user-end plugin allows attackers with FTP or web shell access to escalate privileges to root on shared hosting servers running CloudLinux/CageFS, posing a risk to all user-end plugin versions prior to 2.4.8.
⚙️Technical Details
Affected Systems
Shared hosting servers running CloudLinux/CageFS
Attack Vectors
NETWORK
💥Impact Assessment
Severity: CRITICAL
Who Is at Risk
U.S. government agencies and Federal Civilian Executive Branch (FCEB) agencies
🛡️Recommended Actions
1Update the cPanel user-end plugin to version 2.4.8 or later
2Use the command `grep -rE 'cpanel_jsonapi_func=(generateEcCert|packageUserSize)|cert_action_entry .*geneccert' /usr/local/cpanel/logs/ /var/cpanel/logs/ 2>/dev/null` to check for vulnerability
3Examine system logs for any actions taken by detected IPs
📦Affected Products
Litespeedtech Litespeed Cpanel PluginLitespeedtech Litespeed Whm Plugin
🔐NVD Verified DataVERIFIED
CVE-2026-54420 ↗CVSS 8.5 — HIGH
Attack Vector
NETWORK
Complexity
HIGH
Vector String
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:HWeaknesses
CWE-61
Affected Products (CPE)
Litespeedtech Litespeed Cpanel PluginLitespeedtech Litespeed Whm Plugin
CVE-2026-48172 ↗CVSS 9.8 — CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HWeaknesses
CWE-266
Affected Products (CPE)
Litespeedtech Litespeed Cpanel PluginLitespeedtech Litespeed Whm Plugin
Read the full article
This is a curated summary. The complete article is available at Bleeping Computer.
