www.cisa.gov 6/15/2026, 8:16:44 PM · external

CISA flags LiteSpeed cPanel Plugin UNIX symlink vulnerability

Developing story vulnerability 2 articles tracked
LiteSpeed cPanel Plugin UNIX symlink vulnerability (CVE-2026-54420) exploited
CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Listed in KEV
Patch Patch Available

THE Known Exploited Vulnerabilities (KEV) Catalog is maintained by CISA to assist the cybersecurity community in managing vulnerabilities that have been actively exploited. It is an essential tool for organizations to prioritize their vulnerability management efforts. The catalog features detailed information about known vulnerabilities, including their associated risks and recommended mitigations.

One highlighted vulnerability is CVE-2026-54420, linked to the LiteSpeed cPanel Plugin, which involves a UNIX symbolic link vulnerability. Organizations are urged to follow vendor instructions and CISA guidelines for handling these vulnerabilities, including a specific focus on compliance with BOD 26-04 for risk prioritization. Additionally, the catalog is available in various formats and updates can be subscribed to via CISA's service.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline