Cybersecurity officials are warning about active exploitation of critical vulnerabilities in Joomla and LiteSpeed's cPanel plugin. The Joomla flaw allows unauthenticated attackers to upload malicious files and execute code on servers, while the LiteSpeed vulnerability enables privilege escalation to root access on shared hosting servers. The US Cybersecurity and Infrastructure Security Agency has added both flaws to its Known Exploited Vulnerabilities catalog, giving federal agencies until mid-June to patch their systems, with automated attacks already underway.