The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns that a vulnerability in the LiteSpeed cPanel user-end plugin is being exploited in the wild. CISA cites CVE-2026-54420, which is listed in its Known Exploited Vulnerabilities (KEV) catalog, signaling that the flaw is actively used by attackers. The agency directs U.S. Federal Civilian Executive Branch (FCEB) agencies to remediate the issue by a specified deadline, with reporting indicating June 18, 2026. CISA also urges federal agencies to secure affected servers promptly, framing the remaining time as limited. The vulnerability carries a CVSS score of 8.5, and reporting describes it as enabling root privilege escalation, which would allow an attacker to gain higher-level control of systems running the impacted plugin. CISA’s guidance centers on applying the vendor’s fixes or performing the appropriate mitigations for servers using the LiteSpeed cPanel user-end plugin. The notices emphasize that, because exploitation is ongoing, agencies should prioritize patching and validation of remediation steps rather than waiting for broader incident response timelines.
CISA warns of LiteSpeed cPanel plugin flaw already exploited in attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns that a vulnerability in the LiteSpeed cPanel user-end plugin is being exploited in the wild. CISA cites CVE-2026-54420, which is...
- CISA flags CVE-2026-54420 in the LiteSpeed cPanel user-end plugin as being actively exploited.
- The vulnerability appears in CISA’s Known Exploited Vulnerabilities (KEV) catalog.
- CISA requires Federal Civilian Executive Branch agencies to remediate by June 18, 2026.
- CVE-2026-54420 has a reported CVSS score of 8.5.
- The flaw is described as enabling root privilege escalation.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has given U.S. government agencies three days to secure their servers against an actively exploited vulnerability (CVE-2026-54420) in the LiteSpeed cPanel user-end plugin. [...]
2 months agoThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a security flaw impacting LiteSpeed cPanel Plugin to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by June 18, 2026. The vulnerability in question is CVE-2026-54420 (CVSS score: 8.5), which has been described as a case of privilege
2 months ago
Google announces Gemini 3.5 Transcribe for AI-powered speech-to-text in Chrome
Google announces Gemini 3.5 Transcribe, an AI speech-to-text model that turns spoken input into structured text, and say...
Apple iPhone 18 Pro September event date, lineup and foldable iPhone rumors
Apple is expected to hold its next iPhone-focused event in early September, but it has not confirmed the date or details...
Volvo updates electric cars with connected road-hazard alerts
Volvo is rolling out a software update to three electric models that adds warnings about hazards ahead. The feature aler...