CISA Sets Three-Day Patch Deadline for Actively Exploited LiteSpeed cPanel Plugin Flaw

CVE-2026-54420 lands on the KEV catalog, triggering a BOD 22-01 remediation clock for federal civilian agencies.

ThreatVectr Newsdesk· 2 min read
CISA Sets Three-Day Patch Deadline for Actively Exploited LiteSpeed cPanel Plugin Flaw
Share

The Cybersecurity and Infrastructure Security Agency has added CVE-2026-54420, a flaw in the LiteSpeed cPanel user-end plugin, to its Known Exploited Vulnerabilities catalog and given federal civilian executive branch agencies three days to remediate.

That is an unusually short fuse.

The standard remediation window under Binding Operational Directive 22-01 is two weeks for most KEV entries. CISA retains discretion to shorten that timeline when exploitation activity warrants, and it has done so here. Agencies that cannot patch within the window are directed to discontinue use of the affected product.

The vulnerability sits in the user-end component of the LiteSpeed plugin for cPanel, the control panel software widely deployed across shared hosting providers. CISA's catalog entry confirms active exploitation but, consistent with its usual practice, does not name victims, threat actors, or attribution. The agency lists the due date as three calendar days from the catalog addition, not three business days.

BOD 22-01 binds FCEB agencies. It does not legally bind the private sector. CISA continues to recommend that state, local, tribal and territorial governments — along with critical infrastructure operators — treat KEV entries as a de facto prioritization list. Hosting providers running LiteSpeed-enabled cPanel deployments fall squarely in that recommendation.

This is the second cPanel-adjacent flaw CISA has flagged in recent cycles, signaling sustained attacker interest in the hosting control-plane layer. Plugins that sit between cPanel and a web server are attractive targets: they often run with elevated privileges and touch every tenant on a shared host.

Administrators should consult the LiteSpeed Technologies security advisories page for the fixed plugin version and apply it across all cPanel instances. Where immediate patching is not feasible, disabling the plugin is the documented mitigation. CISA's catalog entry does not list a specific ransomware association, though that field is frequently updated retroactively as incident data matures.

There is no proposed rulemaking attached to this action. KEV additions are administrative, issued under standing BOD authority rather than through notice-and-comment. Agencies have no comment period; the clock runs from publication.

Reporting obligations remain unchanged. Federal agencies experiencing suspected exploitation must notify CISA under existing incident-reporting requirements, and covered critical infrastructure entities should track their separate obligations under the forthcoming CIRCIA final rule, which remains pending at the Department of Homeland Security following its 2024 proposed rulemaking and extended comment period.

Private-sector operators should treat the three-day federal deadline as a signal of exploitation severity, not as a ceiling on their own response time.

© 2026 Threat Vectr