Skip to main content

cPanel Plugin vulnerabilities

1 published alerts for LiteSpeed cPanel Plugin.

Actively exploited (KEV)

CVE-2026-54420

LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability

LiteSpeed cPanel Plugin is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-54420). LiteSpeed cPanel plugin contains a UNIX symbolic link (Symlink) following vulnerability that could allow a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS. CISA remediation due date: 2026-06-18. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.