Home > Control panel > Operations notices > Plesk panel vulnerability (CVE-2026-65642,CVE-2026-65642)

Related Links

Notice Links:

Notice

Plesk panel vulnerability (CVE-2026-65642,CVE-2026-65642)

PostedWed, 26 Aug 2026 03:31 AM UTC
Tue, 25 Aug 2026 23:31 PM EDT
Last UpdateWed, 26 Aug 2026 03:36 AM UTC (5 hours ago)
Tue, 25 Aug 2026 23:36 PM EDT
StatusClosed

Users of Plesk and CPanel packages, are recommended to update to the latest version as soon as possible. This is due to two vulnerabilities, CVE-2026-65642 and CVE-2026-65642

Affected Versions:
Plesk for Linux 18.0.79.7 and earlier
Plesk for Linux 18.0.80 - 18.0.80.3

Patched Versions: 18.0.79.8 & 18.0.80.4

The first CVE may allow an attacker with access to a normal, logged-in user account to gain access to content belonging to another user, or the server. Details on https://support.plesk.com/hc/en-us/articles/42844242102679-Vulnerability-CVE-2026-65642-in-Plesk-s-database-management-interface

The second CVE potentially allows a logged-in-user to run abritrary code with root user privielges. Details on https://support.plesk.com/hc/en-us/articles/42871001389207-Vulnerability-CVE-2026-65647-in-Plesk-s-Site-Import-and-Migrator-extensions

If anyone needs extra help with updates, please open a support ticket at https://rimuhosting.com/ticket/enterticketdetails.jsp

#

Keep You Updated?

Log in to subscribe to changes to this notice.

Set your operation notice contact details for future notifications.