cvedb.io
CVE-2026-54420
HIGH · CVSS 8.5 ⚠ KEV — EXPLOITED
EPSS exploitation probability: 66%
⚠ Listed in the CISA Known Exploited Vulnerabilities catalog — actively exploited.
Published 2026-06-15 · Last modified 2026-07-23T09:10:00.113

Summary

LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS, as exploited in the wild in May 2026.

Affected products

LiteSpeed — cPanel Plugin

Does this affect you?

Add your gear to cvedb and we'll alert you only when LiteSpeed ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.