CISA adds two exploited infrastructure vulnerabilities

CISA has added two actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog. CVE-2026-20262 in Cisco Catalyst SD-WAN Manager carries CVSS 6.5 and allows an authenticated remote attacker with valid credentials and at least write access to create or overwrite files on the underlying filesystem, which can later be used to escalate to root. Cisco PSIRT reported limited exploitation in June and released fixed versions; recommended releases are 20.9.9.2, 20.12.7.2, 20.15.4.5, 20.15.5.3, 20.18.3.1 or 26.1.1.2. CVE-2026-54420, CVSS 8.5, affects the LiteSpeed cPanel plugin before 2.4.8, distributed through LiteSpeed WHM PlugIn before 5.3.2.0, and lets users with FTP or web shell access escalate to root on shared hosting servers running CloudLinux or CageFS. Exploitation was observed in May 2026.

What this means for your organisation

The two items hit different audiences. SD-WAN Manager concerns those running their own connectivity between sites. The LiteSpeed plugin concerns hosting providers and managed service partners, and therefore indirectly everyone whose website sits with such a provider: another tenant on the same server can effectively take over the whole machine. If you have outsourced website operations, this is a question for your supplier rather than your own IT department.

Berigo recommends

  • Upgrade Cisco Catalyst SD-WAN Manager to one of the releases Cisco specifies.
  • Ask your hosting provider in writing whether they run the LiteSpeed cPanel plugin, and which version.
  • Disable the LiteSpeed plugin where upgrading cannot be done quickly, and assess tenant-to-root escalation risk.
  • Use the KEV catalog as your standing basis for patch prioritisation, not CVSS scores alone.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch