The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability affecting the LiteSpeed cPanel Plugin, tracked as CVE-2026-54420, to its Known Exploited Vulnerabilities (KEV) Catalog after confirming active exploitation in the wild. The vulnerability primarily impacts shared hosting environments and presents a significant security risk to servers running CloudLinux with CageFS isolation. Classified as a UNIX symbolic link (symlink) following issue (CWE-61), the flaw can be exploited by attackers who possess limited access to a server, such as valid FTP credentials or a compromised web shell. The vulnerability stems from improper handling and validation of symbolic links during file operations within the LiteSpeed cPanel Plugin. An attacker can create malicious symlinks that point to sensitive files or directories outside of their intended access scope. If these links are followed without proper validation, unauthorized access to restricted files may occur, potentially leading to data exposure, privilege escalation, or compromise of other hosting accounts on the same server. The issue is particularly concerning in multi-tenant hosting environments where strong user isolation is essential for maintaining security. CISA added CVE-2026-54420 to the KEV Catalog on 15 June 2026 and established an expedited remediation timeline under Binding Operational Directive (BOD) 26-04. The agency has emphasized that active exploitation is ongoing and that organizations should prioritize mitigation efforts. Security teams are advised to review vendor updates, implement secure file permission configurations, monitor for suspicious file access activity, and assess internet-facing systems for exposure. The inclusion of this vulnerability in the KEV Catalog highlights the continued focus of threat actors on hosting infrastructure as a means to compromise multiple tenants through a single vulnerable entry point.
Tata Electronics has confirmed that it recently experienced a cybersecurity incident, affecting portions of its information technology environment. According to the company, the is...
Phishing attacks continue to evolve, incorporating advanced techniques such as multi-stage redirects, dynamically loaded content, embedded iframes, and browser-executed scripts. Th...
India based automotive manufacturer Bajaj Auto has disclosed a ransomware incident that impacted its corporate IT environment and the systems of its technology subsidiary, Bajaj Au...