The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns that a vulnerability in the LiteSpeed cPanel user-end plugin is being exploited in the wild. CISA cites CVE-2026-54420, which is listed in its Known Exploited Vulnerabilities (KEV) catalog, signaling that the flaw is actively used by attackers. The agency directs U.S. Federal Civilian Executive Branch (FCEB) agencies to remediate the issue by a specified deadline, with reporting indicating June 18, 2026. CISA also urges federal agencies to secure affected servers promptly, framing the remaining time as limited. The vulnerability carries a CVSS score of 8.5, and reporting describes it as enabling root privilege escalation, which would allow an attacker to gain higher-level control of systems running the impacted plugin. CISA’s guidance centers on applying the vendor’s fixes or performing the appropriate mitigations for servers using the LiteSpeed cPanel user-end plugin. The notices emphasize that, because exploitation is ongoing, agencies should prioritize patching and validation of remediation steps rather than waiting for broader incident response timelines.