Home > Control panel > Operations notices > Plesk panel critical vulnerability (CVE-2026-67394)

Related Links

Notice Links:

Notice

Plesk panel critical vulnerability (CVE-2026-67394)

PostedThu, 27 Aug 2026 23:08 PM UTC
Thu, 27 Aug 2026 19:08 PM EDT
Last UpdateThu, 27 Aug 2026 23:23 PM UTC (12 hours ago)
Thu, 27 Aug 2026 19:23 PM EDT
StatusClosed

Users of Plesk are recommended to update to the latest version as soon as possible. This is due to CVE-2026-67394

Affected Versions:
Plesk for Linux 18.0.34 - 18.0.79.8
Plesk for Linux 18.0.80 - 18.0.80.4
Patched Versions: 18.0.79.9 and 18.0.80.5

The CVE may allow an attacker with access to a normal, logged-in user account to escalate to the root user and access anything or the server. Details on https://support.plesk.com/hc/en-us/articles/42968165026967-CVE-2026-67394-Vulnerability-in-Plesk-allows-privilege-escalation-to-root

If anyone needs extra help with updates, please open a support ticket at https://rimuhosting.com/ticket/enterticketdetails.jsp

#

Keep You Updated?

Log in to subscribe to changes to this notice.

Set your operation notice contact details for future notifications.