PHP · JUNE 2026 · EARLY WARNING

LiteSpeed cPanel Plugin Flaw: Early Warning of Exploited Vulnerability

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
CVE-2026-54420Severity: HIGH

An early warning has been issued regarding a security flaw in the LiteSpeed cPanel Plugin, which appears to be exploited for root privilege escalation. Users of this plugin are advised to take immediate action.

What happened

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has reportedly added a security flaw impacting the LiteSpeed cPanel Plugin to its Known Exploited Vulnerabilities catalog. The vulnerability, identified as CVE-2026-54420, allows a user with FTP or web shell access to escalate privileges to root on shared hosting servers running CloudLinux or CageFS. This flaw affects versions of the LiteSpeed cPanel plugin before 2.4.8.

CISA has urged Federal Civilian Executive Branch (FCEB) agencies to apply the necessary fixes by June 18, 2026. LiteSpeed has released security updates and advised users to upgrade to the latest version of the plugin. To check if your server is vulnerable, run the command: `grep -rE 'cpanel_jsonapi_func=(generateEcCert|packageUserSize)|cert_action_entry.*geneccert' /usr/local/cpanel/logs/ /var/cpanel/logs/ 2>/dev/null`. If the command shows output, further investigation is required to rule out false positives.

It is currently under investigation how the vulnerability is being exploited in the wild and whether any attacks have been successful. Users are advised to consult the primary sources for the most up-to-date information and to ensure they have applied the latest security updates.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If litespeed cpanel plugin is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats