Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Gunra Ransomware Exploits Fortinet VPN Flaws, Bypasses MFA
August 10, 2026
Anthropic Claude: New Security Feature Automates Agent Access Approvals
August 10, 2026
Critical Vulnerability Lets Attackers Bypass MFA in Windows 11 and Entra ID
August 10, 2026
Home/Vulnerabilities/Critical LiteSpeed cPanel Plugin Vulnerability Actively Exploited
Vulnerabilities

Critical LiteSpeed cPanel Plugin Vulnerability Actively Exploited

Key Takeaways A critical zero-day vulnerability (CVE-2026-54420) in the LiteSpeed cPanel user-end plugin is under active exploitation. The flaw allows privilege escalation to root, enabling full...

Jennifer sherman
Jennifer sherman
June 16, 2026 3 Min Read
53 0

Key Takeaways

  • A critical zero-day vulnerability (CVE-2026-54420) in the LiteSpeed cPanel user-end plugin is under active exploitation.
  • The flaw allows privilege escalation to root, enabling full server control, particularly threatening shared hosting environments.
  • The vulnerability impacts only the user-end cPanel plugin, which is bundled with the WHM plugin.
  • A patch is available in cPanel plugin version 2.4.8 (bundled with WHM plugin version 5.3.2.1), and immediate application is strongly recommended.

Critical LiteSpeed cPanel Plugin Zero-Day Actively Exploited for Root Access

A severe zero-day vulnerability affecting the LiteSpeed cPanel user-end plugin is currently being actively exploited in the wild, posing a significant risk to shared hosting providers globally. This critical flaw allows attackers to elevate privileges to root, potentially granting them complete control over compromised servers.

Table Of Content

  • Key Takeaways
  • Critical LiteSpeed cPanel Plugin Zero-Day Actively Exploited for Root Access
  • Vulnerability Details: CVE-2026-54420
  • Exploitation Mechanism and Impact
  • Patch Availability and Mitigation
  • What You Should Do

Vulnerability Details: CVE-2026-54420

The security vulnerability, officially identified as CVE-2026-54420, specifically targets the user-end cPanel plugin. LiteSpeed Technologies has clarified that the WHM plugin itself is not directly affected. However, since the user-end plugin is bundled with the WHM plugin, many installations remain susceptible if not promptly updated.

Researchers at Namecheap were credited with the responsible disclosure of the issue after detecting suspicious activities indicative of exploitation attempts. They subsequently reported their findings to LiteSpeed Technologies.

Exploitation Mechanism and Impact

At its core, CVE-2026-54420 enables an attacker with initial limited access—such as compromised FTP credentials or a web shell—to misuse internal API calls within the cPanel plugin. By manipulating specific functions in an unintended sequence, attackers can bypass the isolation mechanisms provided by CloudLinux’s CageFS, ultimately escalating their privileges to root. This breach effectively compromises tenant isolation in multi-tenant hosting environments, potentially exposing all other users on the same server.

Forensic analysis of observed attacks reveals that threat actors are chaining internal API requests in an abnormal manner, specifically targeting the generateEcCert and packageUserSize functions. These operations typically do not occur in immediate succession. However, in exploitation scenarios, these calls are rapidly and concurrently executed across multiple threads, strongly suggesting the use of automated scripts designed to maximize the success rate of privilege escalation.

Further indicators of compromise include attacks originating from a single IP address that repeatedly targets vulnerable endpoints. Server logs often show detectable anomalies, such as concurrent bursts of 7 to 10 simultaneous requests, which deviate significantly from normal sequential user activity.

Patch Availability and Mitigation

LiteSpeed has promptly addressed the vulnerability by releasing a patch in cPanel plugin version 2.4.8, which is bundled with WHM plugin version 5.3.2.1. This update corrects improper access controls and enhances API handling to prevent exploitation. Administrators are strongly advised to apply this update without delay to mitigate the high risk of compromise.

For systems where immediate patching is not feasible, LiteSpeed recommends temporarily removing the user-end plugin to eliminate the attack surface. The flaw was initially reported on May 31, 2026, leading to rapid action from LiteSpeed and cPanel to mitigate the issue. A patched version was released on June 1, 2026, and the CVE identifier was officially assigned on June 14, 2026.

Security experts emphasize the severe potential impact of this vulnerability, particularly within multi-tenant hosting environments where a single compromised account could lead to a complete server takeover. Beyond patching, administrators should conduct thorough log analysis to identify any signs of prior exploitation, including unauthorized privilege changes, suspicious command execution, or unexpected system file modifications.

LiteSpeed has publicly acknowledged Namecheap’s contribution to identifying the vulnerability and has also credited the cPanel team for their swift response and mitigation efforts. Given the active exploitation, timely patching and continuous proactive monitoring are crucial to prevent further incidents.

What You Should Do

  • Update Immediately: Apply the patch by updating to LiteSpeed cPanel plugin version 2.4.8 (bundled with WHM plugin version 5.3.2.1). Refer to the official LiteSpeed security advisory for detailed instructions.
  • Temporary Mitigation: If immediate patching is not possible, temporarily uninstall or remove the user-end LiteSpeed cPanel plugin to eliminate the attack surface.
  • Monitor Logs: Conduct thorough audits of server logs for suspicious activity, including abnormal sequences of API calls (e.g., generateEcCert followed by packageUserSize), concurrent bursts of requests from single IP addresses, unauthorized privilege changes, and unexpected system file modifications.
  • Review Access: Audit and tighten access controls for cPanel users, especially those with FTP credentials or potential web shell access.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityThreatVulnerabilityzero-day

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

Critical Cisco SD-WAN vManage Bug Exploited in Zero-Day Attacks

Next Post

LockBit Alumni and Qilin Drive Ransomware Ecosystem Consolidation

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
CISA Warns of Progress LoadMaster Command Injection Vulnerability Exploited in Attacks
August 10, 2026
Critical Red Hat ACM Vulnerability Lets Attackers Gain Cluster-Admin Access
August 10, 2026
GitHub Expands Malware Detection to 8 Package Registries
August 10, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Emy Elsamnoudy
Emy Elsamnoudy
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us