GDS Africa
← All articles
GDS Africa

Are your Cisco switches and hosting platforms on CISA's active threat list?

Two critical vulnerabilities now flagged as actively exploited—what West African enterprises need to know about their exposure.

This piece references reporting from Security Affairs ↗ . The commentary and analysis are our own.

When the U.S. Cybersecurity and Infrastructure Security Agency (CISA) formally adds a flaw to its Known Exploited Vulnerabilities catalog, it’s a signal that attackers aren’t just theorising—they’re actively weaponising the bug. This week, two vulnerabilities crossed that threshold: a Cisco Catalyst switching vulnerability and a flaw in the LiteSpeed cPanel plugin used by many web hosting providers.

For West African enterprises, this matters more than it might initially appear.

Your infrastructure may be more exposed than you think

Many organisations across Ghana, Nigeria, and the broader region rely on Cisco switching infrastructure—whether directly managed or embedded in data centre and cloud environments. If your network hasn’t been patched against this Catalyst flaw, your switches become a potential entry point for lateral movement and reconnaissance. Similarly, if your organisation hosts applications on shared cPanel-based servers (common in regional hosting), the LiteSpeed plugin vulnerability could allow attackers to escalate privileges or exfiltrate data.

The risk isn’t hypothetical. Once a vulnerability lands on CISA’s active exploitation list, threat actors prioritise scanning for unpatched instances. In environments with limited security operations capacity—a reality for many mid-market firms in West Africa—detection lags behind exploitation.

What to do now

First, audit your infrastructure. Identify which Cisco Catalyst models and cPanel instances are in use, and check patch status immediately. If you’re running either technology, assume you’re being scanned.

Second, don’t patch in isolation. A rushed update without proper testing can break business continuity. GDS Africa helps enterprises across the region manage this balance—we can assess your current exposure, plan staged patching that minimises downtime, and ensure your security posture hardens without disrupting operations.

Third, treat this as a reminder to strengthen your broader security monitoring. Vulnerabilities will keep appearing on CISA’s list. The organisations that survive are those with visibility into what’s running, who can patch systematically, and who have security teams (whether internal or managed) watching for suspicious activity.

Heading into 2027, the attack surface for West African enterprises is only widening. Staying ahead means moving faster than the threat actors—and that requires both the right tools and the right partners.

Let's work together

Talk to our team about cloud, security, networking or managed services for your business.

Get in touch