Home > Control panel > Operations notices

Related Links

Notice Links:

Notices

Plesk panel critical vulnerability (CVE-2026-68487/CVE-2026-68488 )

PostedFri, 11 Sep 2026 00:29 AM UTC
Thu, 10 Sep 2026 20:29 PM EDT
Last UpdateFri, 11 Sep 2026 00:30 AM UTC (27 hours ago)
Thu, 10 Sep 2026 20:30 PM EDT
StatusClosed

Users of Plesk are recommended to update to the latest version as soon as possible. This is due to CVE-2026-68487 and CVE-2026-68488

Affected Versions:
Plesk for Linux 18.0.79.10 and earlier
Plesk for Linux 18.0.80 - 18.0.80.6
Patched Versions:
Plesk for Linux - 18.0.79.11
Plesk for Linux - 18.0.80.7

Both CVE may allow an authenticated user to write arbitrary root-owned files to the host filesystem, leading to full server compromise.

Details on:
https://support.plesk.com/hc/en-us/articles/43248841638551-Vulnerability-in-Plesk-s-Backup-Manager-unsigned-backup-header-allows-path-traversal
https://support.plesk.com/hc/en-us/articles/43248932867351-Vulnerability-in-Plesk-s-Backup-Manager-symlink-race-during-restore-allows-root-privilege-escalation

If anyone needs extra help with updates, please open a support ticket at https://rimuhosting.com/ticket/enterticketdetails.jsp

#

CPanel vulnerability (CVE-2026-67401)

PostedWed, 9 Sep 2026 01:30 AM UTC
Tue, 8 Sep 2026 21:30 PM EDT
Last UpdateWed, 9 Sep 2026 01:30 AM UTC (74 hours ago)
Tue, 8 Sep 2026 21:30 PM EDT
StatusClosed

Cpanel has asked all users to update servers running their hosting panel, due to a security issue CVE-2026-67401

ref: https://support.cpanel.net/hc/en-us/articles/43187903921559-Security-CVE-2026-67401-SQL-Injection-Vulnerability-in-cPanel-s-EmailTrack-Functionality-September-8-2026

This issue is fixed in the following releases:
110: v11.110.0.143
134: v11.134.0.55
136: v11.136.0.39
138: v11.138.0.4
wp138: v11.138.1.9

The vulnerability could allow a mail-enabled cPanel account to write a root-owned file at an arbitrary path on the server, compromising server integrity. We are not aware of any exploitation of these vulnerabilities, but we recommend treating this issue as urgent and updating without delay.

In most cases CPanel will have automatically updated itself. Anyone who requires addtional help to complete this update, please open a support ticket with us https://rimuhosting.com/ticket/enterticketdetails.jsp

#