• Debian 11 is approaching its end-of-life (vendor EOL date - August 31, 2026). Plesk Obsidian 18.0.80 will be the last release to support it.
    If you are running Plesk Obsidian on Debian 11, we recommend you upgrade those servers to Debian 12 using our dist-upgrade tool.
  • We plan to deprecate and remove the support for XML RPC protocol versions earlier than 1.6.9.1 in Plesk Obsidian 18.0.82. We strongly recommend that you update all existing integrations using earlier versions of the XML RPC protocol to comply with the version 1.6.9.1 specification.

nginx

  1. R

    Issue Three more CVEs for nginx just hit - one rated as critical with DoS and RCE possible

    Just a quick note that three more CVEs for nginx have been posted as of yesterday the 15th, with one rated as a major severity with a CVSS v4.0 score of 9.2 (Critical) and a CVSS v3.1 base score of 8.1 (High) Reference: https://cybersecuritynews.com/f5-patches-multiple-nginx-vulnerabilities/...
  2. T

    Issue Bug: Plesk Nginx proxy stripping performance headers - CPU spikes on all woocommerce downloads

    Bug overview: We have discovered that Plesk is stripping off the X-Acccel and Xsendfile headers added by woocommerce for faster secure downloadable products. This means the woocommerce_uploads folder cannot be restricted using the recommended Nginx settings - Meaning downloads can be stolen...
  3. T

    Issue [BUG] sw-nginx 1.30.1 (CVE-2026-42945 patch) crashes with SIGABRT on AlmaLinux 9.7 + OpenSSL 3.5.1

    Hi, I'd like to report a reproducible crash of sw-nginx 1.30.1 that was introduced as part of the CVE-2026-42945 security patch rollout via Plesk. Environment at time of crash: - Plesk Obsidian 18.0.77.2 - AlmaLinux 9.7 - OpenSSL 3.5.1 (installed via dnf automatic updates) -...
  4. D

    Resolved CVE-2026-9256 NGINX ngx_http_rewrite_module vulnerability

    See https://www.cve.org/CVERecord?id=CVE-2026-9256 . I saw that Cpanel already fixed the issue https://support.cpanel.net/hc/en-us/articles/40670279527831-Security-CVE-2026-9256-ea-nginx-v1-31-1-Security-Release-May-22-2026 When does Plesk?
  5. R

    Resolved CVE-2026-42945 Nginx Rift and older Wordpress Toolkit heads up

    A PSA for anyone running older releases of Plesk with nginx, and older releases of Wordpress Toolkit (wp-toolkit) like: 5.8.1-5837. I was auditing one of my older systems today for any rewrites that are vulnerable to the brand new nginx CVE-2026-42945 published a few hours ago today, that can...
  6. ink169

    Resolved no nginx settings on domain view - please help :)

    Hello! i have a subdomain which was working on an app on port 3000 just fine now i have added another one and went to the 'Apache & nginx' setings but there are no nginx options.. How can i verify that nginx is running please I tried running nginxmgr --status from the...
Back
Top