惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

V
Visual Studio Blog
博客园 - 司徒正美
博客园_首页
Jina AI
Jina AI
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
月光博客
月光博客
I
InfoQ
M
MIT News - Artificial intelligence
T
Tailwind CSS Blog
L
LangChain Blog
Last Week in AI
Last Week in AI
A
About on SuperTechFans
B
Blog
博客园 - 叶小钗
雷峰网
雷峰网
H
Help Net Security
WordPress大学
WordPress大学
大猫的无限游戏
大猫的无限游戏
博客园 - 【当耐特】
云风的 BLOG
云风的 BLOG
Microsoft Azure Blog
Microsoft Azure Blog
小众软件
小众软件
aimingoo的专栏
aimingoo的专栏
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻

Cyber Security News

AIRecon: AI-Powered Penetration Testing Tool with Kali Linux Sandbox Critical Chrome Vulnerabilities Allow Attackers to Execute Arbitrary Code - Update Now! Hackers Use Rokarolla Android Malware to Disable Google Play Protect and Control Devices UNC3753 Uses Screen-Sharing Sessions and RMM Tools to Exfiltrate Sensitive Legal Data New OnionDrop Loader Campaign Uses gainmsg C2 to Deliver LegionLoader Payloads ClickFix Campaign Uses EtherHiding and GULoader to Infect Windows Users via Fake CAPTCHA Ghostwriter Hackers Abuse Gmail Admin-Themed Emails to Steal Credentials and 2FA Codes The Half-Life of Threat Intelligence: When Does an IOC Stop Being Useful? Critical Fortinet FortiSandbox Vulnerabilities Actively Exploited in Attacks Aembit Extends IAM for Agentic AI to Microsoft Copilot Studio India Temporarily Bans Telegram Messenger Over Medical Exam Fraud Microsoft 365 Device Code Phishing Campaign Bypasses Password Theft With Legitimate Login Flow AppViewX Launches Agent Identity Security to Govern Agents for the AI and Quantum Era Hackers Weaponize Microsoft Teams Relay to Hide Ransomware Traffic Developer laptops are the credential store attackers are picking through in 2026, GitGuardian announces Endpoint Protection Interlock and Rhysida Ransomware Operations Share Supper Backdoor and Malware Codebase Novo Nordisk Confirms Cyber Attack — Hackers Accessed Patient Medical Data and Internal AI Assets Russian and Chinese Influence Actors Use AI to Evade Bot Detection and Mimic Human Behavior Microsoft Teams Analyze the Wi-Fi Hotspot Data Connected to an Employee’s Device PRC-Nexus Hackers Exploit REDCap Servers to Spy on US Medical Research Institutions Infinite Campus Data Breach Exposes 137,000 Users Personal Details OptinMonster Plugin Hack Exposes 1.2 Million Wordpress Sites to Cyberattack Ransomware Ecosystem Consolidates Around LockBit Alumni, Qilin, Hyflock, and The Gentlemen Hackers Abuse Legitimate RMM Tools in The Quarry IRS and SSA Phishing Campaigns Cisco SD-WAN vManage Vulnerability Exploited in Zero-Day Attacks Nearly 14,000 SimpleHelp Servers Exposed Amid Critical Authentication Bypass Disclosure Microsoft Site Showing Warning Following Certificate Expiry DPAPISnoop Tool Extracts CREDHIST Hashes for Offline Windows Credential Recovery SHADOWBYT3$ Allegedly Claim Breach of Nintendo, Stealing Sensitive Data Anthropic Updated Privacy Policy to Include Identity Verification for Claude Users
LiteSpeed cPanel Plugin 0-Day Vulnerability Actively Expl...
Abinaya · 2026-06-16 · via Cyber Security News

A critical zero-day vulnerability in the LiteSpeed cPanel user-end plugin is being actively exploited in the wild, posing a serious threat to shared hosting environments worldwide.

The flaw, tracked as CVE-2026-54420, enables privilege escalation to root level, allowing attackers to take full control of affected servers under specific conditions.

LiteSpeed cPanel Plugin Zero-Day Vulnerability

According to LiteSpeed Technologies, the vulnerability impacts only the user-end cPanel plugin and does not affect the WHM plugin itself.

However, since the user-end plugin is bundled with the WHM plugin, many environments may still be exposed if not updated.

The issue was responsibly disclosed by researchers at Namecheap, who observed suspicious behavior linked to exploitation attempts before reporting it to the vendor.

At its core, the vulnerability allows an attacker with limited initial access, such as FTP credentials or access to a compromised web shell, to abuse internal API calls within the cPanel plugin.

By chaining specific functions in unintended ways, attackers can bypass the privilege boundaries enforced by CloudLinux’s CageFS isolation and ultimately escalate their privileges to root.

This effectively breaks tenant isolation in shared hosting setups, potentially exposing other users hosted on the same server.

Analysis of exploitation patterns shows that attackers are leveraging abnormal sequences of internal API requests, particularly involving the generateEcCert and packageUserSize functions.

Under normal conditions, these operations are not executed in immediate succession. However, in observed attacks, these calls are deliberately chained together in rapid bursts, often executed concurrently across multiple threads.

This behavior suggests the use of automated exploitation scripts designed to increase the likelihood of successful privilege escalation.

Further forensic indicators indicate that attackers typically originate from a single source IP that repeatedly targets both vulnerable endpoints.

Concurrent bursts of 7–10 simultaneous requests unlike normal sequential user activity create detectable anomalies in server logs that defenders can use to identify attacks.

LiteSpeed has released a patch in cPanel plugin version 2.4.8, bundled with WHM plugin version 5.3.2.1, which addresses the vulnerability by correcting improper access controls and tightening API handling.

Administrators are strongly urged to apply the update immediately, as unpatched systems remain at high risk of compromise.

For systems that cannot be updated immediately, removing the user-end plugin is recommended as a temporary mitigation step to eliminate the attack surface.

Reported on May 31, 2026, the flaw prompted rapid action from LiteSpeed and cPanel, which quickly mitigated and removed the vulnerable component.

A patched version was released on June 1, 2026, and the CVE identifier was officially assigned on June 14, 2026.

Security experts warn that the real-world impact of this vulnerability could be severe, particularly in multi-tenant environments, where a single compromised account could result in a full server takeover.

Administrators are advised not only to patch but also to conduct thorough log analysis to identify any signs of prior exploitation, including unauthorized privilege changes, suspicious command execution, or unexpected modifications to system files.

LiteSpeed has acknowledged Namecheap’s contribution to identifying the issue and has credited the cPanel team for their swift mitigation efforts.

Given the active exploitation status, timely patching and proactive monitoring remain essential to prevent further incidents.

Follow us on Google NewsLinkedIn, and X to Get More Instant Updates.

Abinaya

Abinayahttps://cybersecuritynews.com/

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.