Dear Customer,

Plesk has released security updates addressing three critical vulnerabilities that could allow unauthorized access to server files and databases, and in some cases allow an authenticated hosting user to obtain root-level control of the server.

We strongly recommend that all customers operating their own Plesk servers update Plesk and the affected extensions immediately.

Affected vulnerabilities

CVE-2026-65646 – DNS Zone Management
May allow a hosting user with DNS management access to read arbitrary server files and potentially obtain Plesk administrator and database credentials.

Patched Plesk versions:

  • 18.0.79.8

  • 18.0.80.4

  • Any later version

CVE-2026-65642 – Database Management Interface
May allow an authenticated Plesk user to access, modify, or delete databases belonging to other customers on the same server.

Patched Plesk versions:

  • 18.0.79.8

  • 18.0.80.4

  • Any later version

CVE-2026-65647 – Site Import / Plesk Migrator
May allow an unprivileged Plesk user to execute arbitrary code with root privileges, potentially compromising the entire server and all hosted subscriptions.

Patched extension versions:

  • Plesk Migrator 2.36.0 or later

  • Site Import 1.12.1 or later

Action Required

  1. Log in to your Plesk server.

  2. Go to Tools & Settings → Updates and Upgrades.

  3. Install all available Plesk updates.

  4. Update Plesk Migrator and Site Import from Extensions → My Extensions.

  5. Verify that Plesk is running 18.0.79.8, 18.0.80.4, or later.

Because of the severity of these vulnerabilities, we recommend applying these updates as soon as possible.

Best Regards,

CCI Hosting Support Team

 



Wednesday, August 26, 2026

« Back