SECURITYTHE HACKER NEWS
CISA Flags LiteSpeed cPanel Plugin Flaw Exploited for Root Privilege Escalation
CISA added a vulnerability in LiteSpeed cPanel Plugin to its KEV catalog, requiring FCEB agencies to fix it by June 18, 2026. The flaw, CVE-2026-54420 (CVSS score 8.5), involves privilege escalation exploited for root access.
Mentioned
Related Signal
Adjacent reporting
- CISA Adds Actively Exploited Linux Root Access Bug CVE-2026-31431 to KEV
- Microsoft Warns of Two Actively Exploited Defender Vulnerabilities
- New Linux 'Copy Fail' Vulnerability Enables Root Access on Major Distributions
- Google June 2026 Android Update Patches 124 Flaws, One Actively Exploited
- Microsoft Patches Critical ASP.NET Core CVE-2026-40372 Privilege Escalation Bug
- Dirty Frag gets a sequel as Fragnesia hands Linux attackers root-level access