LiteSpeed cPanel CVE-2026-54420 in KEV: symlink path to root, second LiteSpeed cPanel KEV in 3 weeks
CISA added CVE-2026-54420 — a CVSS 8.5 symlink-following bug in the LiteSpeed cPanel plugin — to KEV on June 15. Federal patch deadline: June 18.
CISA added CVE-2026-54420 — a CVSS 8.5 symlink-following bug in the LiteSpeed cPanel plugin — to KEV on June 15. Federal patch deadline: June 18.
A privilege-escalation flaw in the LiteSpeed User-End cPanel plugin lets any cPanel account execute arbitrary scripts as root. Mass scanning began within 72 hours of disclosure.