CISA has added the actively exploited CVE-2026-54420 vulnerability in the LiteSpeed cPanel plugin to its KEV catalog and given federal agencies three days to patch. The high-severity flaw enables root privilege escalation on shared hosting servers and continues a pattern of LiteSpeed cPanel issues targeted in attacks.

Attackers with FTP or web shell access can escalate privileges to root on servers running CloudLinux or CageFS.
This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.
Federal agencies face another tight patching window under BOD 26-04, underscoring how quickly cPanel plugin flaws move from discovery to active exploitation in the wild.
Tap a lens to see what this story means for you.
Reader-supported · Daily Brief
Daily brief at 7 AM ET. Top tech stories, every morning. Sourced and fact-checked.
Reader-supported
The Circuitry is a passion project I've always wanted to build, and I love the work behind it.
Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.
Any contribution is appreciated. If not, no pressure. Thanks for reading.
Apple CEO Tim Cook has told The Wall Street Journal that price increases are unavoidable as the company can no longer absorb massive hikes in memory and storage costs driven by AI demand. The shift is expected to affect the iPhone 18 lineup and other devices later this year, marking the latest sign of industry-wide RAM shortages.
SpaceX has appointed longtime Elon Musk ally Roelof Botha as an independent director and audit committee member days after its record IPO. The move adds a key Sequoia Capital figure to a board where Musk holds overwhelming voting control.
Elon Musk has exercised the full 2018 Tesla CEO compensation award, securing 303,960,630 shares for an approximate $116 billion paper gain according to an SEC filing. No shares were sold during the transaction and the acquired stock remains restricted until 2028.