LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-54420: LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jun 15, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jun 18, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-54420 to its Known Exploited Vulnerabilities catalog on Jun 15, 2026, with a federal patch deadline of Jun 18, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

LiteSpeed cPanel plugin contains a UNIX symbolic link (Symlink) following vulnerability that could allow a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS.

This vulnerability affects the LiteSpeed cPanel Plugin and stems from improper handling of symbolic links on UNIX-like systems. It could allow an attacker who already has FTP or web shell access on a shared hosting server using CloudLinux with CageFS to follow links to files outside their intended directory. The issue matters for shared hosting environments because it can expand the reach of a compromised low-privileged account without requiring additional remote exploits.

How it works

The weakness is classified as CWE-61, a UNIX symbolic link following vulnerability. In this class of flaw, an application processes a file path that an attacker can replace with a symbolic link pointing to a different location. An attacker with FTP or web shell access on the affected shared server can create or modify a link that the plugin then follows, potentially reading or writing files outside the user's restricted environment. Specific mechanics of exploitation and any required conditions must be confirmed against the vendor advisory.

Am I affected? How to find it in your systems

The LiteSpeed cPanel Plugin is typically deployed on shared web hosting servers that integrate with cPanel and run CloudLinux with CageFS. Inventory should begin by identifying all servers that have this plugin installed through cPanel's plugin management interface or by checking package lists on the host operating system. Review configurations for any custom symlink-related settings or relaxed CageFS policies. Because exact affected versions are not provided here, confirm the precise range and configuration requirements against the vendor advisory. Look for unusual file access patterns in web server or FTP logs that reference paths outside expected user directories, though such indicators alone do not confirm exploitation.

How to remediate

Apply the vendor-supplied update for the LiteSpeed cPanel Plugin as the primary remediation step. After patching, review and tighten CageFS and CloudLinux configurations to enforce stricter symlink handling for all hosted accounts. Disable or restrict FTP and shell access for accounts that do not require it, and audit existing symlink permissions across user directories. All specific patch identifiers and configuration changes should be verified directly in the vendor advisory.

If you can't patch immediately

Until the update can be applied, reduce exposure by isolating affected shared hosting servers from less trusted networks through segmentation. Consider disabling the LiteSpeed cPanel Plugin on systems where its functionality is not essential. Enable additional monitoring for file system operations that cross user boundaries and review CISA BOD 26-04 guidance for prioritization and cloud service requirements. If mitigations cannot be implemented, evaluate discontinuing use of the plugin as noted in the required actions.

If your data may have been exposed

Actively exploited vulnerabilities of this type can lead to unauthorized file access and subsequent data exposure. Organizations can run a free exposure scan of their domains and associated email addresses against known breach data to determine whether any credentials or records have already appeared in public datasets.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedLiteSpeed · cPanel Plugin
WeaknessCWE-61
Added to CISA KEVJun 15, 2026
Federal patch deadlineJun 18, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities