CVE-2026-54420CISA KEVEPSS p70.5%

CVE-2026-54420LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability

LiteSpeed / cPanel Plugin

Description

LiteSpeed cPanel plugin contains a UNIX symbolic link (Symlink) following vulnerability that could allow a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS.

Scoring

CVSS 8.5 ()
VectorCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS1.44% probability of exploitation · percentile 70.5% · 2026-08-02T12:03:13Z
Last modified2026-07-23

CISA KEV entry

Added to KEV: 2026-06-15

Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.