LiteSpeed cPanel Plugin Zero-Day Under Active Exploitation
Want more insights like this?
A critical vulnerability in the LiteSpeed cPanel user-end plugin is being actively exploited, threatening shared hosting environments globally. Tracked as CVE-2026-54420, the flaw lets attackers with limited access — like stolen FTP credentials — bypass CloudLinux's CageFS isolation and escalate all the way to root, potentially exposing every site on a shared server. CISA has flagged it as actively exploited.
Namecheap researchers discovered the issue after spotting suspicious API call patterns: rapid concurrent chaining of the generateEcCert and packageUserSize functions across multiple threads.
LiteSpeed patched it on June 1, 2026 — in user-end plugin version 2.4.8 and WHM plugin version 5.3.2.1. Update both immediately, or remove the user-end plugin as a stopgap. And because exploitation started before the patch existed, review your logs for those API call patterns: updating now won't tell you whether you were already hit.
Source: Cybersecurity News