Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
OptinMonster Hack Exposes 1.2M WordPress Plugin Million
June 16, 2026
Hackers Abuse RMM Tools in The Quarry IRS/SSA Legitimate Phishing
June 16, 2026
Ransomware Ecosystem Consolidates: LockBit, Q Around Alumni
June 16, 2026
Home/Vulnerabilities/Critical LiteSpeed cPanel 0-Day Actively Plugin Vulnerability
Vulnerabilities

Critical LiteSpeed cPanel 0-Day Actively Plugin Vulnerability

A critical zero-day vulnerability in the LiteSpeed cPanel user-end plugin is under active exploitation in the wild. The flaw poses a serious threat to shared hosting environments worldwide. The flaw,...

Jennifer sherman
Jennifer sherman
June 16, 2026 3 Min Read
2 0

A critical zero-day vulnerability in the LiteSpeed cPanel user-end plugin is under active exploitation in the wild. The flaw poses a serious threat to shared hosting environments worldwide.

The flaw, tracked as CVE-2026-54420, enables privilege escalation to root level, allowing attackers to take full control of affected servers under specific conditions.

LiteSpeed cPanel Plugin Zero-Day Vulnerability

According to LiteSpeed Technologies, the vulnerability impacts only the user-end cPanel plugin and does not affect the WHM plugin itself.

However, since the user-end plugin is bundled with the WHM plugin, many environments may still be exposed if not updated.

The issue was responsibly disclosed by researchers at Namecheap, who observed suspicious behavior linked to exploitation attempts before reporting it to the vendor.

At its core, the vulnerability allows an attacker with limited initial access, such as FTP credentials or access to a compromised web shell, to abuse internal API calls within the cPanel plugin.

By chaining specific functions in unintended ways, attackers can bypass the privilege boundaries enforced by CloudLinux’s CageFS isolation and ultimately escalate their privileges to root.

This effectively breaks tenant isolation in shared hosting setups, potentially exposing other users hosted on the same server.

Analysis of exploitation patterns shows that attackers are leveraging abnormal sequences of internal API requests, particularly involving the generateEcCert and packageUserSize functions.

Under normal conditions, these operations are not executed in immediate succession. However, in observed attacks, these calls are deliberately chained together in rapid bursts, often executed concurrently across multiple threads.

This behavior suggests the use of automated exploitation scripts designed to increase the likelihood of successful privilege escalation.

Further forensic indicators indicate that attackers typically originate from a single source IP that repeatedly targets both vulnerable endpoints.

Concurrent bursts of 7–10 simultaneous requests unlike normal sequential user activity create detectable anomalies in server logs that defenders can use to identify attacks.

LiteSpeed has released a patch in cPanel plugin version 2.4.8, bundled with WHM plugin version 5.3.2.1, which addresses the vulnerability by correcting improper access controls and tightening API handling.

Administrators are strongly urged to apply the update immediately, as unpatched systems remain at high risk of compromise.

For systems that cannot be updated immediately, removing the user-end plugin is recommended as a temporary mitigation step to eliminate the attack surface.

Reported on May 31, 2026, the flaw prompted rapid action from LiteSpeed and cPanel, which quickly mitigated and removed the vulnerable component.

A patched version was released on June 1, 2026, and the CVE identifier was officially assigned on June 14, 2026.

Security experts warn that the real-world impact of this vulnerability could be severe, particularly in multi-tenant environments, where a single compromised account could result in a full server takeover.

Administrators are advised not only to patch but also to conduct thorough log analysis to identify any signs of prior exploitation, including unauthorized privilege changes, suspicious command execution, or unexpected modifications to system files.

LiteSpeed has acknowledged Namecheap’s contribution to identifying the issue and has credited the cPanel team for their swift mitigation efforts.

Given the active exploitation status, timely patching and proactive monitoring remain essential to prevent further incidents.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityThreatVulnerabilityzero-day

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

Cisco SD-WAN vManage Zero-Day Vulner Vulnerability Exploited

Next Post

Ransomware Ecosystem Consolidates Around LockBit Alumni, Qilin,

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Cisco SD-WAN vManage Zero-Day Vulner Vulnerability Exploited
June 16, 2026
Critical SimpleHelp Auth Bypass Exposes 14, Nearly Servers
June 16, 2026
Microsoft Site Warning: Certificate Expiry Causes Issues
June 15, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Emy Elsamnoudy
Emy Elsamnoudy
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Detects Critical MongoDB CVE-

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us