Home > Control panel > Operations notices > Plesk panel critical update for CVE-2026-64636 and CVE-2026-64637

Related Links

Notice Links:

Notice

Plesk panel critical update for CVE-2026-64636 and CVE-2026-64637

PostedFri, 7 Aug 2026 04:36 AM UTC
Fri, 7 Aug 2026 00:36 AM EDT
Last UpdateFri, 7 Aug 2026 04:52 AM UTC (10 hours ago)
Fri, 7 Aug 2026 00:52 AM EDT
StatusOpen

Plesk has asked all users update servers running their hosting panel, due to a signiificant security issue, designated CVE-2026-64636 and CVE-2026-64637

These issues affect all Plesk versions prior to 18.0.79.5.

Further details and recommended actions for these two vulnerabilities can be found at ...

https://support.plesk.com/hc/en-us/articles/42431868205079-CVE-2026-64636-Vulnerability-in-Plesk-blind-SQL-injection
https://support.plesk.com/hc/en-us/articles/42432168683799-CVE-2026-64637-Authentication-Bypass-Leading-to-Privilege-Escalation-in-Plesk

Where possible we have automatically updated customers plesk installations to bring them up to date.

Anyone who requires help to complete this update, please open a support ticket with us https://rimuhosting.com/ticket/enterticketdetails.jsp

#

Keep You Updated?

Log in to subscribe to changes to this notice.

Set your operation notice contact details for future notifications.