CISA warns of another cPanel plugin flaw exploited in attacks
CISA issued a directive for U.S. agencies to patch CVE-2026-54420, a vulnerability in the LiteSpeed cPanel plugin, actively exploited in the wild. Agencies have 72 hours to secure servers and mitigate risks tied to this flaw.
This flaw highlights the importance of securing third-party integrations within hosting environments. Agencies should prioritize patching and review plugin configurations for broader exposure mitigation.
CISA has flagged CVE-2026-54420, a critical vulnerability in the LiteSpeed cPanel plugin, as actively exploited. The agency's alert mandates federal agencies to patch affected systems within three days to prevent further compromise.
The vulnerability reportedly allows attackers to execute remote code and gain unauthorized access to cPanel-managed hosting environments. Its exploitation underscores the risks of unpatched third-party plugins in sensitive infrastructures.
Organizations outside of government should also assess their exposure to this flaw. Applying patches and hardening plugin configurations can reduce the risk of exploitation, especially for businesses relying on cPanel for web hosting.