Dear Customer, Plesk has released security updates addressing three critical vulnerabilities that could allow unauthorized access to server files and databases, and in some cases allow an authenticated hosting user to obtain root-level control of the server. We strongly recommend that all customers operating their own Plesk servers update Plesk ... Read More »
Severity: Critical (CVSS 10) Affected Systems: Affected products listed in the NVD and vendor advisory Overview A critical vulnerability identified as CVE-2026-76604 has been disclosed. Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.3 - The PHP form element is vulnerable to the ... Read More »
Severity: Critical (CVSS 10) Affected Systems: Affected products listed in the NVD and vendor advisory Overview A critical vulnerability identified as CVE-2026-76605 has been disclosed. Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.3 - ???. Risk CVSS and CISA data indicate the following: CVSS attack ... Read More »
Severity: Critical (CVSS 10) Affected Systems: Affected products listed in the NVD and vendor advisory Overview A critical vulnerability identified as CVE-2026-76606 has been disclosed. Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.3 - ???. Risk CVSS and CISA data indicate the following: CVSS attack vector is ... Read More »
