GHSA-3g44-c4qc-cxm8 · Severity: high — LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0)...
LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS, as exploited in the wild in May 2026.
Conclusion & alert: CVE-2026-54420 is rated Critical Active Threat (82.6/100): CVSS High severity, with medium exploitation likelihood (EPSS 1.26%). Core evidence: CISA KEV confirms active exploitation (added 2026-06-15) affecting LiteSpeed / cPanel Plugin. a weakness (CWE-61) Unauthenticated remote administrative access may be possible. Mandatory action: The CISA remediation deadline has passed—treat as an emergency patch priority.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
: LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability · CISA KEV detail
: 2026-06-15
: 2026-06-18
: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-23 | 0.65% | 1.26% | +0.61% |
| 2 | 2026-06-17 | 0.61% | 0.65% | +0.04% |
| 3 | 2026-06-16 | — | 0.61% | — |
Full EPSS history (5 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.5 | 3.1 | HIGH |
|
1.8 | 6.0 | [email protected] |
GHSA-3g44-c4qc-cxm8 · Severity: high — LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0)...
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| litespeedtech | litespeed_cpanel_plugin | < 2.4.8 | cpe:2.3:a:litespeedtech:litespeed_cpanel_plugin:*:*:*:*:*:*:*:* |
| litespeedtech | litespeed_whm_plugin | < 5.3.2.0 | cpe:2.3:a:litespeedtech:litespeed_whm_plugin:*:*:*:*:*:*:*:* |