← العودة للجدول
CVE-2026-54420
CVE-2026-54420 — LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn bef
📅 2026-06-14
🟠 High 🔥 Yes NVD Exploit Linux CVSS 8.5

📋 الوصف الكامل

LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS, as exploited in the wild in May 2026.

💻 الأنظمة المتأثرة

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-54420

📡 المصدر

NVD

✅ الحلول والتخفيف

Refer to CVE-2026-54420 NVD advisory

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←