Home > Control panel > Operations notices > Plesk panel critical vulnerability (CVE-2026-68487/CVE-2026-68488 )

Related Links

Notice Links:

Notice

Plesk panel critical vulnerability (CVE-2026-68487/CVE-2026-68488 )

PostedFri, 11 Sep 2026 00:29 AM UTC
Thu, 10 Sep 2026 20:29 PM EDT
Last UpdateFri, 11 Sep 2026 00:30 AM UTC (28 hours ago)
Thu, 10 Sep 2026 20:30 PM EDT
StatusClosed

Users of Plesk are recommended to update to the latest version as soon as possible. This is due to CVE-2026-68487 and CVE-2026-68488

Affected Versions:
Plesk for Linux 18.0.79.10 and earlier
Plesk for Linux 18.0.80 - 18.0.80.6
Patched Versions:
Plesk for Linux - 18.0.79.11
Plesk for Linux - 18.0.80.7

Both CVE may allow an authenticated user to write arbitrary root-owned files to the host filesystem, leading to full server compromise.

Details on:
https://support.plesk.com/hc/en-us/articles/43248841638551-Vulnerability-in-Plesk-s-Backup-Manager-unsigned-backup-header-allows-path-traversal
https://support.plesk.com/hc/en-us/articles/43248932867351-Vulnerability-in-Plesk-s-Backup-Manager-symlink-race-during-restore-allows-root-privilege-escalation

If anyone needs extra help with updates, please open a support ticket at https://rimuhosting.com/ticket/enterticketdetails.jsp

#

Keep You Updated?

Log in to subscribe to changes to this notice.

Set your operation notice contact details for future notifications.