Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Vulnerability Found in LiteSpeed cPanel Plugin

Critical Vulnerability Found in LiteSpeed cPanel Plugin

Posted on June 16, 2026 By CWS

A significant zero-day vulnerability has been identified in the LiteSpeed cPanel plugin, which is currently being actively exploited, posing a serious risk to shared hosting environments globally.

Understanding the LiteSpeed Plugin Vulnerability

Recognized as CVE-2026-54420, this flaw permits privilege escalation to root level, potentially allowing attackers to assume complete control of affected servers under certain conditions. While the vulnerability exclusively impacts the user-end cPanel plugin, environments using WHM may also be at risk due to the plugin bundle.

This issue was responsibly disclosed by Namecheap researchers, who detected unusual activity indicative of exploitation attempts before notifying the developer.

Mechanism of the Exploit

The vulnerability enables attackers with minimal initial access, such as FTP credentials or a compromised web shell, to exploit internal API calls within cPanel. By creatively linking certain functions, attackers can bypass CloudLinux’s CageFS isolation, escalating their privileges to root and compromising tenant isolation on shared servers.

Investigations reveal that attackers utilize atypical sequences of API requests, particularly targeting the generateEcCert and packageUserSize functions. In these attacks, operations that are typically not executed together are intentionally chained in quick succession, suggesting the use of automated scripts.

Mitigation and Recommendations

LiteSpeed has released a fix in cPanel plugin version 2.4.8, which comes with WHM plugin version 5.3.2.1, effectively addressing the vulnerability by enhancing access controls and API management. Administrators are urged to implement this update immediately to mitigate risks.

For systems unable to update instantly, it is recommended to temporarily remove the user-end plugin to reduce exposure. Security experts emphasize the necessity of thorough log analysis to detect any signs of past exploitation, such as unauthorized privilege changes or suspicious system file modifications.

Importance of Immediate Action

Reported on May 31, 2026, the vulnerability prompted quick responses from LiteSpeed and cPanel, leading to a patched release on June 1, 2026, with the CVE designation assigned on June 14, 2026. The potential impact in multi-tenant environments could be severe, making timely patching and vigilant monitoring crucial to preventing further incidents.

LiteSpeed acknowledges Namecheap’s role in identifying the issue and commends the cPanel team for their rapid mitigation actions. Administrators are strongly advised to patch systems promptly and to remain vigilant through proactive monitoring.

Cyber Security News Tags:cPanel, CVE-2026-54420, Cybersecurity, Exploit, LiteSpeed, Plugin, security patch, server security, Vulnerability, zero-day

Post navigation

Previous Post: North Korean Hackers Use Fake Microsoft Alerts to Spread NarwhalRAT
Next Post: Tech Alliance ‘Athena’ Secures Open Source Software

Related Posts

SquidLoader Using Sophisticated Malware With Near-Zero Detection to Swim Under Radar SquidLoader Using Sophisticated Malware With Near-Zero Detection to Swim Under Radar Cyber Security News
20+ Malicious Apps on Google Play Actively Attacking Users to Steal Login Credentials 20+ Malicious Apps on Google Play Actively Attacking Users to Steal Login Credentials Cyber Security News
Severe Wazuh Flaw Allows Critical Security Breaches Severe Wazuh Flaw Allows Critical Security Breaches Cyber Security News
Critical HPE Telco Service Activator Security Flaw Exposed Critical HPE Telco Service Activator Security Flaw Exposed Cyber Security News
IT Giant Ingram Micro Restores Operations Following Ransomware Attack IT Giant Ingram Micro Restores Operations Following Ransomware Attack Cyber Security News
LANSCOPE Endpoint Manager Vulnerability Let Attackers Execute Remote Code LANSCOPE Endpoint Manager Vulnerability Let Attackers Execute Remote Code Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Telegram Desktop Update Fixes Critical JavaScript Flaw
  • UK Introduces Passkeys for 23 Million GOV.UK Users
  • 3BB Network Breach: MeshCentral Backdoor Exploited
  • Massive Vite Server Vulnerability Exploited for Cloud Credential Theft
  • Red Heron Uses Gitea Exploit to Breach Global Firms

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Telegram Desktop Update Fixes Critical JavaScript Flaw
  • UK Introduces Passkeys for 23 Million GOV.UK Users
  • 3BB Network Breach: MeshCentral Backdoor Exploited
  • Massive Vite Server Vulnerability Exploited for Cloud Credential Theft
  • Red Heron Uses Gitea Exploit to Breach Global Firms

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark