Exploited in the wild LiteSpeed cPanel user-end plugin privilege-escalation WHM plugin CISA patch-tuesday
CISA warns of another cPanel plugin flaw exploited in attacks
CVE Tools coverage
CISA has directed U.S. federal agencies to patch within three days a actively exploited vulnerability in the LiteSpeed cPanel user-end plugin, tracked as CVE-2026-54420. Reported as CVE-2026-48172, the high-severity flaw affects user-end plugin versions before 2.4.8 and can let attackers with FTP or web shell access escalate to root on shared hosting systems running CloudLinux/CageFS due to a UNIX symlink-following issue. This is included in CISA’s Known Exploited Vulnerabilities Catalog, making timely remediation critical to reduce the risk of widespread compromise.