<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=10643465&amp;fmt=gif">

LiteSpeed cPanel Plugin Zero-Day Under Active Exploitation

Critical vulnerability in the LiteSpeed cPanel plugin threatens global shared hosting; update the user-end plugin to 2.4.8 and the WHM plugin to 5.3.2.1.
Content Team

A critical vulnerability in the LiteSpeed cPanel user-end plugin is being actively exploited, threatening shared hosting environments globally. Tracked as CVE-2026-54420, the flaw lets attackers with limited access — like stolen FTP credentials — bypass CloudLinux's CageFS isolation and escalate all the way to root, potentially exposing every site on a shared server. CISA has flagged it as actively exploited.

Namecheap researchers discovered the issue after spotting suspicious API call patterns: rapid concurrent chaining of the generateEcCert and packageUserSize functions across multiple threads.

LiteSpeed patched it on June 1, 2026 — in user-end plugin version 2.4.8 and WHM plugin version 5.3.2.1. Update both immediately, or remove the user-end plugin as a stopgap. And because exploitation started before the patch existed, review your logs for those API call patterns: updating now won't tell you whether you were already hit.

Source: Cybersecurity News

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo