CISA warns of another cPanel plugin flaw exploited in attacks
2026-06-16T13:23:29Z•fd26e3d0a908099766138d9cd00175eb2e0821b89c381f4b15ace750e2d7cadc
CISACiscoFortinetLiteSpeedMicrosoft TeamsSimpleHelpWordPressactive-exploitationcPaneldata-breachmalwareransomwaresupply-chainvulnerabilityzero-day
What happened
Multiple actively exploited vulnerabilities, ransomware tactics, supply-chain compromises, and data breaches were reported. CISA warned of an actively exploited LiteSpeed cPanel plugin flaw (CVE-2026-54420). Defused reported attackers exploiting critical Fortinet FortiSandbox flaws. Cisco patched a vManage zero-day (CVE-2026-20262) that was used for privilege escalation. DragonForce ransomware abused Microsoft Teams relay infrastructure to hide C2 traffic. A Windows variant of SprySOCKS targeted government organizations. Supply-chain compromises impacted WordPress plugins served via a CDN (Opt
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- fd26e3d0a908099766138d9cd00175eb2e0821b89c381f4b15ace750e2d7cadc
- Enrichment time
- 2026-06-16T13:23:29Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.