惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

月光博客
月光博客
Stack Overflow Blog
Stack Overflow Blog
L
LangChain Blog
Jina AI
Jina AI
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
雷峰网
雷峰网
T
Tailwind CSS Blog
MongoDB | Blog
MongoDB | Blog
博客园 - 【当耐特】
博客园 - 聂微东
V
Visual Studio Blog
博客园_首页
Engineering at Meta
Engineering at Meta
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
The Cloudflare Blog
人人都是产品经理
人人都是产品经理
Apple Machine Learning Research
Apple Machine Learning Research
阮一峰的网络日志
阮一峰的网络日志
Microsoft Security Blog
Microsoft Security Blog
GbyAI
GbyAI
F
Fortinet All Blogs
C
Check Point Blog
罗磊的独立博客
H
Hackread – Cybersecurity News, Data Breaches, AI and More

Cyber Security News

AIRecon: AI-Powered Penetration Testing Tool with Kali Linux Sandbox Critical Chrome Vulnerabilities Allow Attackers to Execute Arbitrary Code - Update Now! UNC3753 Uses Screen-Sharing Sessions and RMM Tools to Exfiltrate Sensitive Legal Data New OnionDrop Loader Campaign Uses gainmsg C2 to Deliver LegionLoader Payloads ClickFix Campaign Uses EtherHiding and GULoader to Infect Windows Users via Fake CAPTCHA Ghostwriter Hackers Abuse Gmail Admin-Themed Emails to Steal Credentials and 2FA Codes The Half-Life of Threat Intelligence: When Does an IOC Stop Being Useful? Critical Fortinet FortiSandbox Vulnerabilities Actively Exploited in Attacks Aembit Extends IAM for Agentic AI to Microsoft Copilot Studio India Temporarily Bans Telegram Messenger Over Medical Exam Fraud Microsoft 365 Device Code Phishing Campaign Bypasses Password Theft With Legitimate Login Flow AppViewX Launches Agent Identity Security to Govern Agents for the AI and Quantum Era Hackers Weaponize Microsoft Teams Relay to Hide Ransomware Traffic Developer laptops are the credential store attackers are picking through in 2026, GitGuardian announces Endpoint Protection Interlock and Rhysida Ransomware Operations Share Supper Backdoor and Malware Codebase Novo Nordisk Confirms Cyber Attack — Hackers Accessed Patient Medical Data and Internal AI Assets Russian and Chinese Influence Actors Use AI to Evade Bot Detection and Mimic Human Behavior Microsoft Teams Analyze the Wi-Fi Hotspot Data Connected to an Employee’s Device PRC-Nexus Hackers Exploit REDCap Servers to Spy on US Medical Research Institutions Infinite Campus Data Breach Exposes 137,000 Users Personal Details OptinMonster Plugin Hack Exposes 1.2 Million Wordpress Sites to Cyberattack Ransomware Ecosystem Consolidates Around LockBit Alumni, Qilin, Hyflock, and The Gentlemen Hackers Abuse Legitimate RMM Tools in The Quarry IRS and SSA Phishing Campaigns LiteSpeed cPanel Plugin 0-Day Vulnerability Actively Exploited in the Wild Cisco SD-WAN vManage Vulnerability Exploited in Zero-Day Attacks Nearly 14,000 SimpleHelp Servers Exposed Amid Critical Authentication Bypass Disclosure Microsoft Site Showing Warning Following Certificate Expiry DPAPISnoop Tool Extracts CREDHIST Hashes for Offline Windows Credential Recovery SHADOWBYT3$ Allegedly Claim Breach of Nintendo, Stealing Sensitive Data Anthropic Updated Privacy Policy to Include Identity Verification for Claude Users
CISA Adds LiteSpeed cPanel Plugin Vulnerability to KEV Li...
Abinaya · 2026-06-19 · via Cyber Security News

CISA has added a critical LiteSpeed cPanel Plugin vulnerability, tracked as CVE-2026-54420, to its Known Exploited Vulnerabilities (KEV) catalog following evidence of active exploitation in the wild.

The flaw affects shared hosting environments and poses a significant risk to servers running CloudLinux with CageFS isolation. The vulnerability is classified as a UNIX symbolic link (symlink) following the issue, mapped to CWE-61.

It allows attackers with limited access, such as FTP credentials or a web shell, to exploit improper symlink handling within the LiteSpeed cPanel plugin.

This weakness could enable unauthorized access to sensitive files outside of restricted directories, potentially leading to privilege escalation or data exposure across shared hosting accounts.

According to CISA, the vulnerability was officially added to the KEV list on June 15, 2026, with a remediation due date of June 18, 2026, under Binding Operational Directive (BOD) 26-04.

LiteSpeed cPanel Plugin Vulnerability

This directive mandates that federal agencies and associated organizations prioritize remediation of actively exploited vulnerabilities. Technical analysis indicates that the issue arises when the plugin fails to validate symbolic links during file operations properly.

In shared hosting environments, attackers can create malicious symlinks pointing to sensitive system files or other users’ data. If the server follows these links without validation, it may inadvertently expose restricted resources.

This type of vulnerability is particularly dangerous in multi-tenant environments, such as web hosting servers, where user isolation is critical.

Although CloudLinux CageFS is designed to contain users within isolated file systems, improper symlink handling can bypass these protections if not properly mitigated.

While no confirmed attribution links CVE-2026-54420 to ransomware campaigns, CISA has emphasized that active exploitation is already occurring. Threat actors commonly exploit such vulnerabilities to gain initial access, conduct lateral movement, or exfiltrate data.

CISA recommends that organizations immediately apply vendor-provided mitigations and follow secure configuration practices.

Administrators should review LiteSpeed plugin updates, enforce strict file permission policies, and turn off unsafe symlink behaviors where possible.

Continuous monitoring for suspicious file access patterns and unexpected symlink creation is also advised. Additionally, organizations must comply with CISA’s Forensics Triage Requirements to ensure proper incident response readiness.

This includes maintaining logs, monitoring access controls, and preparing for rapid investigation in the event of a compromise.

If mitigations are unavailable, CISA advises organizations to consider discontinuing use of affected products until a secure solution is implemented.

Stakeholders are also encouraged to evaluate internet-facing assets and prioritize patching based on exposure and risk level.

Security teams should treat this vulnerability as a high priority due to its exploitation status and potential impact on shared hosting infrastructure.

The inclusion of CVE-2026-54420 in the KEV catalog highlights the growing trend of attackers targeting hosting platforms to compromise multiple tenants through a single entry point.

Organizations using LiteSpeed with cPanel are urged to act immediately to reduce the risk of compromise and ensure compliance with federal cybersecurity directives.

Follow us on Google NewsLinkedIn, and X to Get More Instant Updates.

Abinaya

Abinayahttps://cybersecuritynews.com/

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.