[Important] Plesk Security Advisory: Two Critical Vulnerabilities identified, Hotfix Available - Action Required for unmanaged servers

Resolved
Resolved

All webhosting, reseller webhosting and managed servers are updated and protected against these vulnerabilities.

Avatar for
Investigating

Note: all managed, webhosting and reseller hosting servers have been updated and are protected against these vulnerabilities.

We would like to inform you that two security vulnerabilities affecting Plesk have been identified. Hotfixes are now available.

Blind SQL Injection - CVE-2026-64636

Reseller Privilege Escalation to Root - CVE-2026-64637

Action Required for unmanaged servers only (not for web/reseller hosting or managed servers):

Update Plesk Now

  1. Log into Plesk.

  2. Go to tools and settings > Updates and upgrades.

  3. Install the latest Plesk updates to update to version 18.0.79.5 or later.

  4. Verify the installed version under Tools & Settings > Server Components. 

Mitigation: 

If you are unable to update immediately, you can reduce risk from this issue by either of the following:

  • Disabling OS-level system logins for resellers by setting systemAdmin = off under the [login] section of Panel.ini
  • Disabling API access for reseller accounts via the relevant service plan permission.

We strongly recommend updating the latest hotfix version as soon as possible.

Avatar for
Began at:

Affected components
  • VPS
  • Webservers