CISA KEV mitigation for LiteSpeed cPanel Plugin (CVE-2026-54420)
Advisory/Mitigation
Summary
Hide ▲
Show ▼
CISA put CVE-2026-54420 in LiteSpeed cPanel Plugin on the KEV catalog, ordering FCEB agencies to apply fixes by June 18, 2026. The flaw is a CVSS 8.5 privilege-escalation issue that can turn FTP or web shell access into root on shared hosting servers running CloudLinux/CageFS. LiteSpeed says affected builds include LiteSpeed cPanel Plugin before 2.4.8 and LiteSpeed WHM PlugIn before 5.3.2.0, with a fix in LiteSpeed WHM Plugin v5.3.2.1 bundled with cPanel plugin v2.4.8 or higher.
Related Happenings
CISA KEV order for FCEB agencies on LiteSpeed cPanel flaw
Public Sector Action
H score36
First: 16.06.2026 13:47
Last: 16.06.2026 13:47
Sources 1
How related:
On Monday, CISA also added that the vulnerability to its Known Exploited Vulnerabilities Catalog (KEV), ordering Federal Civilian Executive Branch (FCEB) agencies to secure their systems within three days, as required by Binding Operational Directive (BOD) 26-04.
About this happening:
CISA added the LiteSpeed cPanel user-end plugin flaw to KEV and ordered Federal Civilian Executive Branch agencies to secure systems within three days under ...
CISA KEV order for FCEB agencies on LiteSpeed cPanel flaw
Public Sector ActionHow related: On Monday, CISA also added that the vulnerability to its Known Exploited Vulnerabilities Catalog (KEV), ordering Federal Civilian Executive Branch (FCEB) agencies to secure their systems within three days, as required by Binding Operational Directive (BOD) 26-04.
About this happening: CISA added the LiteSpeed cPanel user-end plugin flaw to KEV and ordered Federal Civilian Executive Branch agencies to secure systems within three days under ...
Fortinet security patch release for CVE-2026-39813
Security Patch Release
H score41
First: 16.06.2026 12:19
Last: 16.06.2026 12:19
Sources 1
About this happening:
Fortinet released April 14 security updates for FortiSandbox, covering CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089. The patch release fixes three...
Fortinet security patch release for CVE-2026-39813
Security Patch ReleaseAbout this happening: Fortinet released April 14 security updates for FortiSandbox, covering CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089. The patch release fixes three...
LiteLLM v1.83.14-stable security fix release (multiple vulnerabilities)
Security Patch Release
H score42
First: 15.06.2026 19:39
Last: 15.06.2026 19:39
Sources 1
About this happening:
BerriAI shipped LiteLLM v1.83.14-stable to close a three-CVE chain that could let a low-privilege proxy user reach full admin and run code on the server. The u...
LiteLLM v1.83.14-stable security fix release (multiple vulnerabilities)
Security Patch ReleaseAbout this happening: BerriAI shipped LiteLLM v1.83.14-stable to close a three-CVE chain that could let a low-privilege proxy user reach full admin and run code on the server. The u...
LiteLLM proxy privilege-escalation and RCE chain (multiple vulnerabilities)
Vulnerability
H score37
First: 15.06.2026 19:39
Last: 15.06.2026 19:39
Sources 1
About this happening:
LiteLLM proxy now has a disclosed three-CVE chain that lets a low-privilege user reach proxy_admin and run code on the server, putting provider keys and stored credent...
LiteLLM proxy privilege-escalation and RCE chain (multiple vulnerabilities)
VulnerabilityAbout this happening: LiteLLM proxy now has a disclosed three-CVE chain that lets a low-privilege user reach proxy_admin and run code on the server, putting provider keys and stored credent...
SolarWinds security patch release for CVE-2026-28318
Security Patch Release
H score82
First: 05.06.2026 22:15
Last: 05.06.2026 22:15
Sources 1
About this happening:
SolarWinds released Serv-U 15.5.4 Hotfix 1 for CVE-2026-28318, an actively exploited denial-of-service flaw that can crash exposed Serv-U servers. The update fixes...
SolarWinds security patch release for CVE-2026-28318
Security Patch ReleaseAbout this happening: SolarWinds released Serv-U 15.5.4 Hotfix 1 for CVE-2026-28318, an actively exploited denial-of-service flaw that can crash exposed Serv-U servers. The update fixes...
Timeline
-
16.06.2026 08:41 1 articles · 29d ago
Namecheap brings CVE-2026-54420 in LiteSpeed cPanel Plugin to attention
Attribution UpdateNamecheap is credited with bringing CVE-2026-54420 in LiteSpeed cPanel Plugin to attention on May 31, 2026. The flaw affects shared hosting servers running CloudLinux/CageFS and can let a user with FTP or web shell access escalate privileges to root.
Show sources
- CISA Flags LiteSpeed cPanel Plugin Flaw Exploited for Root Privilege Escalation — thehackernews.com — 16.06.2026 08:41
-
16.06.2026 08:41 3 articles · 29d ago
CISA adds CVE-2026-54420 in LiteSpeed cPanel Plugin to the KEV catalog
Legal Policy Action UpdateCISA added CVE-2026-54420 in LiteSpeed cPanel Plugin to its Known Exploited Vulnerabilities catalog and required Federal Civilian Executive Branch agencies to apply the fixes by June 18, 2026. LiteSpeed advised upgrading to LiteSpeed WHM Plugin v5.3.2.1 bundled with cPanel plugin v2.4.8 or higher to patch the privilege-escalation flaw.
Show sources
- CISA Flags LiteSpeed cPanel Plugin Flaw Exploited for Root Privilege Escalation — thehackernews.com — 16.06.2026 08:41
- CISA Flags LiteSpeed cPanel Plugin Flaw Exploited for Root Privilege Escalation — thehackernews.com — 16.06.2026 08:41
- CISA warns of another cPanel plugin flaw exploited in attacks — www.bleepingcomputer.com — 16.06.2026 13:47