IT Consultancy
IT Consultancy Get expert guidance to leverage technology for your business growth. We help you identify the right IT solutions, optimize infrastructure, and ensure your digital environment is secure,…
make IT easy

IT Consultancy Get expert guidance to leverage technology for your business growth. We help you identify the right IT solutions, optimize infrastructure, and ensure your digital environment is secure,…
Digital Marketing Grow your brand and reach the right audience with data-driven marketing strategies. We help you create campaigns that convert, manage social channels effectively, and optimize your d…
Privacy Policy At CometSoul, accessible from https://cometsoul.com, one of our main priorities is the privacy of our visitors. This Privacy Policy document contains types of information that is collec…
Welcome to CometSoul! These terms and conditions outline the rules and regulations for the use of CometSoul’s Website, located at https://cometsoul.com. By accessing this website we assume you a…
If you require any more information or have any questions about our site’s disclaimer, please feel free to contact us. Disclaimers for CometSoul All the information on this website – https…
Managed Wi-Fi Service Build a fast, stable, and secure Wi-Fi for your business at Zero depreciation cost. Enterprise-Grade Guest Wi-Fi With $0 Upfront Hardware Costs. We provide, install, and support …
Smart Business System Integrator Simplify your daily operations with smart systems that automate bookings, schedules, and routine tasks so you can focus on growing your business. We set up and integra…

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity LiteSpeed cPanel Plugin vulnerability to its Known Exploited Vulnerabilities (KEV) catalog. The flaw, tracked as CVE-2026-54420, is being actively exploited and could allow attackers to gain root-level privileges on vulnerable hosting servers.
CVE-2026-54420 is a privilege escalation vulnerability affecting LiteSpeed cPanel Plugin versions earlier than 2.4.8 and LiteSpeed WHM Plugin versions earlier than 5.3.2.0. The issue stems from improper handling of symbolic links (symlinks) in shared hosting environments running CloudLinux or CageFS. (NVD)
According to security advisories, an attacker with existing FTP or web shell access can exploit the flaw to bypass security restrictions and potentially gain root access to the server.
Root-level access gives attackers complete control over a system. Once compromised, a threat actor may be able to:
Because many web hosting providers use LiteSpeed and cPanel, the impact could extend to multiple customer accounts hosted on the same server.
The vulnerability affects:
LiteSpeed has already released patched versions that address the issue.
Organizations using LiteSpeed cPanel Plugin should prioritize patching immediately. CISA has classified the flaw as actively exploited, making remediation urgent. (Navanem)
Recommended actions include:
The addition of CVE-2026-54420 to CISA’s KEV catalog highlights the seriousness of this vulnerability. Since attackers are already exploiting the flaw in real-world environments, administrators running LiteSpeed cPanel Plugin should apply security updates as soon as possible to prevent privilege escalation and potential server compromise.
Source: https://thehackernews.com/2026/06/cisa-flags-litespeed-cpanel-plugin-flaw.html