2 vulnerabilities across 2 products scored HIGH or above on June 14, 2026.
- HIGH: 2
[HIGH] litespeed_technologies/cpanel_plugin
1 CVE | CVSS 3.1: 8.5 | AAS 11.0
cpe:2.3:a:litespeed_technologies:cpanel_plugin:*:*:*:*:*:*:*:*(< 2.4.8)
LiteSpeed cPanel plugin versions before 2.4.8 (as distributed in LiteSpeed WHM Plugin before 5.3.2.0) mishandle symlinks on shared hosting servers running CloudLinux/CageFS, allowing attackers with FTP or web shell access to bypass security controls (CVE-2026-54420, CVSS 8.5). This vulnerability has been actively exploited since May 2026. Hosting providers and system administrators managing shared hosting environments should immediately update to patched versions via https://blog.litespeedtech.com/2026/06/01/security-update-for-litespeed-cpanel-plugin-2/.
- CVE-2026-54420 (CVSS 3.1: 8.5)
[HIGH] liambindle/mqtt-c
1 CVE | CVSS 4.0: 7.8 | AAS 9.2
cpe:2.3:a:liambindle:mqtt-c:*:*:*:*:*:*:*:*(< 1.1.6)
LiamBindle MQTT-C through version 1.1.6 contains a heap-based out-of-bounds read and integer underflow in the mqtt_unpack_publish_response() function (CVE-2026-54412, CVSS 7.8), allowing remote attackers controlling an MQTT broker or able to inject traffic into unencrypted sessions to crash MQTT-C clients and potentially disclose adjacent heap memory via a crafted PUBLISH packet. Developers and organizations using MQTT-C in IoT, embedded, or messaging applications should immediately update to a patched version and encrypt MQTT connections to reduce exposure. Check the LiamBindle MQTT-C repository for available updates.
- CVE-2026-54412 (CVSS 4.0: 7.8)