Home > Control panel > Operations notices > Plesk panel critical vulnerability (CVE-2026-67397)

Related Links

Notice Links:

Notice

Plesk panel critical vulnerability (CVE-2026-67397)

PostedThu, 3 Sep 2026 22:44 PM UTC
Thu, 3 Sep 2026 18:44 PM EDT
Last UpdateThu, 3 Sep 2026 22:45 PM UTC (12 hours ago)
Thu, 3 Sep 2026 18:45 PM EDT
StatusClosed

Users of Plesk are recommended to update to the latest version as soon as possible. This is due to CVE-2026-67397

Affected Versions:
Plesk for Linux 18.0.79.9 or earlier
Plesk for Linux 18.0.80 - 18.0.80.5
Patched Versions:
Plesk for Linux - 18.0.79.10
Plesk for Linux - 18.0.80.6

The CVE may allow an attacker with access to a normal, logged-in user account to escalate to the root user. Details on https://support.plesk.com/hc/en-us/articles/43070000520855-Vulnerability-CVE-2026-67397-Arbitrary-code-execution-as-root-in-Plesk

If anyone needs extra help with updates, please open a support ticket at https://rimuhosting.com/ticket/enterticketdetails.jsp

#

Keep You Updated?

Log in to subscribe to changes to this notice.

Set your operation notice contact details for future notifications.