CVE Tools

CISA warns of another cPanel plugin flaw exploited in attacks

BleepingComputerBy Sergiu Gatlan

Reported exploitedLiteSpeed cPanel user-end pluginWHM plugin

Our summary

CISA has directed U.S. federal agencies to patch within three days a actively exploited vulnerability in the LiteSpeed cPanel user-end plugin, tracked as CVE-2026-54420. Reported as CVE-2026-48172, the high-severity flaw affects user-end plugin versions before 2.4.8 and can let attackers with FTP or web shell access escalate to root on shared hosting systems running CloudLinux/CageFS due to a UNIX symlink-following issue. This is included in CISA’s Known Exploited Vulnerabilities Catalog, making timely remediation critical to reduce the risk of widespread compromise.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store