All webhosting, reseller webhosting and managed servers are updated and protected against these vulnerabilities.
Note: all managed, webhosting and reseller hosting servers have been updated and are protected against these vulnerabilities.
We would like to inform you that two security vulnerabilities affecting Plesk have been identified. Hotfixes are now available.
Blind SQL Injection - CVE-2026-64636
An attacker could extract data from the server database through a read-only SQL injection.
Affected Versions: Plesk Versions 18.0.51 up to 18.0.79.4
Fixed Versions: Plesk 18.0.80.1 and Plesk 18.0.79.5
Support Link: https://support.plesk.com/hc/en-us/articles/42431868205079
Reseller Privilege Escalation to Root - CVE-2026-64637
An attacker with Reseller-level access could gain Root-level privileges on the server.
Affected Versions: All Plesk Versions below 18.0.79.5
Fixed Versions: Plesk 18.0.80.1 and Plesk 18.0.79.5
Support Link: https://support.plesk.com/hc/en-us/articles/42432168683799
Update Plesk Now
Log into Plesk.
Go to tools and settings > Updates and upgrades.
Install the latest Plesk updates to update to version 18.0.79.5 or later.
Verify the installed version under Tools & Settings > Server Components.
If you are unable to update immediately, you can reduce risk from this issue by either of the following:
We strongly recommend updating the latest hotfix version as soon as possible.
We’ll find your subscription and send you a link to login to manage your preferences.
We've sent you an email — please check your inbox and click the link to continue.
We’ll use your email to save your preferences so you can update them later.
Subscribe to other services using the bell icon on the subscribe button on the status page.
You’ll no long receive any status updates from Yourwebhoster.eu, are you sure?
{{ error }}
We’ll no longer send you any status updates about Yourwebhoster.eu.
Your email has been verified — you'll now receive status updates from Yourwebhoster.eu.