Web hosts are scrambling to fix the bug under active attack by hackers. One company said hackers have been abusing the bug for months.
CISA added CVE-2026-54420 to KEV, requiring federal agencies to patch LiteSpeed cPanel root escalation by June 18, 2026.
Attackers can exploit a “critical” security vulnerability in the cPanel and WebHost Manager (WHM) web server administration software to gain unauthorized access. So far, there are no reports of ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results