INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

cPanel plugin flaw exploited for root privilege escalation

| 2026-06-16 08:53 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical alert regarding the exploitation of an actively used vulnerability in LiteSpeed cPanel user-end plugins, posing significant risks to federal enterprises. The CVE-2026-48172 flaw allows attackers with FTP or web shell access to escalate privileges to root on shared hosting servers running CloudLinux/CageFS. CISA warns that users must update their server software within three days of receiving the alert and advises against using a specific command to check for vulnerability, as it may indicate exploitation. The agency has also issued a binding operational directive requiring federal agencies to prioritize patching based on risk, with older directives revoked.
Technical Mitigations AI-generated
* Regularly update and patch all plugins, including cPanel user-end plugin (bundled with WHM) to the latest version, as recommended by CISA. * Use a web application firewall (WAF) or intrusion detection system (IDS) to detect and prevent attacks targeting CVE-2026-48172 vulnerability in LiteSpeed cPanel plugins. * Implement secure authentication and authorization mechanisms to limit access to shared hosting servers running CloudLinux/CageFS, such as using IP blocking or rate limiting on FTP and web shell access. * Monitor system logs for any suspicious activity, including actions taken by detected IPs, to detect potential exploitation of CVE-2026-48172 vulnerability.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

5.3.•••.•••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-20262CVE-2026-20262 CVE-2026-48172CVE-2026-48172 CVE-2026-54420CVE-2026-54420
Target & Sectors
NORTH_AMERICA NORTH_AMERICA governmentgovernment
Incident Timeline
‎2026/05/17
Threat actors used a known exploit of the LiteSpeed cPanel plugin to target U.S. CISA.
attribution LiteSpeed cPanel
attribution CVE-2026-48172
attribution CISA
‎May 31, 2026
Threat actors exploited known vulnerabilities in Cisco Catalyst and LiteSpeed cPanel plugins.
‎2026/06/15
Threat actors exploited a vulnerability in Cisco Catalyst network equipment and LiteSpeed cPanel plugin to gain unauthorized access.
‎Jun 16, 2026
Threat actors exploited vulnerabilities in Cisco Catalyst network equipment and LiteSpeed cPanel plugin to gain unauthorized access.
‎2026/06/16
LiteSpeed cPanel plugin vulnerabilities affect all user-end plugin versions before 2.4.8 and allow attackers with FTP or web shell access to gain root privileges.
organisation CVSS
organisation Cisco Catalyst SD-WAN
organisation Path Traversal Vulnerability CVE-2026
organisation LiteSpeed
organisation cPanel
organisation CloudLinux
organisation WHM
organisation LiteSpeed WHM Plugin v5.3.2.1
organisation FTP
infrastructure 2.4.8
organisation UNIX
organisation CloudLinux/CageFS
organisation IP
organisation LiteSpeed WHM
organisation EDR
financial 04 BOD
organisation UI
‎June 18, 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a security flaw in the LiteSpeed cPanel plugin to its Known Exploited Vulnerabilities catalog, requiring federal agencies by June 18, 2026.
attribution the LiteSpeed cPanel
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
attribution KEV
attribution FCEB
attribution Federal Civilian Executive Branch
attribution Vulnerability /
tactic T1584.004 - Server
general_metric 16  Jun
‎June 29, 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered federal agencies to patch the Cisco Catalyst plugin vulnerability by June 29, 2026.
target_region United States
Tactical Metrics
Metrics
infrastructure
‎2.4.8
Software Version
Metrics
financial
4
Bod