CISA warns of another cPanel plugin flaw exploited in attacks

2026-06-16T13:23:29Zfd26e3d0a908099766138d9cd00175eb2e0821b89c381f4b15ace750e2d7cadc
CISACiscoFortinetLiteSpeedMicrosoft TeamsSimpleHelpWordPressactive-exploitationcPaneldata-breachmalwareransomwaresupply-chainvulnerabilityzero-day

What happened

Multiple actively exploited vulnerabilities, ransomware tactics, supply-chain compromises, and data breaches were reported. CISA warned of an actively exploited LiteSpeed cPanel plugin flaw (CVE-2026-54420). Defused reported attackers exploiting critical Fortinet FortiSandbox flaws. Cisco patched a vManage zero-day (CVE-2026-20262) that was used for privilege escalation. DragonForce ransomware abused Microsoft Teams relay infrastructure to hide C2 traffic. A Windows variant of SprySOCKS targeted government organizations. Supply-chain compromises impacted WordPress plugins served via a CDN (Opt

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
fd26e3d0a908099766138d9cd00175eb2e0821b89c381f4b15ace750e2d7cadc
Enrichment time
2026-06-16T13:23:29Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.