• Debian 11 is approaching its end-of-life (vendor EOL date - August 31, 2026). Plesk Obsidian 18.0.80 will be the last release to support it.
    If you are running Plesk Obsidian on Debian 11, we recommend you upgrade those servers to Debian 12 using our dist-upgrade tool.
  • We plan to deprecate and remove the support for XML RPC protocol versions earlier than 1.6.9.1 in Plesk Obsidian 18.0.82. We strongly recommend that you update all existing integrations using earlier versions of the XML RPC protocol to comply with the version 1.6.9.1 specification.

Input Critical security updates need technical details

Fede Marsell

Basic Pleskian
Server operating system version
AlmaLinux 8
Plesk version and microupdate number
18.0.80#4
Hello,

I don't think the current way of communicating critical security updates is sufficient for system administrators.

For Plesk Obsidian 18.0.80 Update 4, the only information currently available is:

Plesk Obsidian 18.0.80 Update 4 — 24 August 2026
This update addresses a critical security issue. We strongly recommend that you apply it as soon as possible.
Note: More details to follow shortly.

Of course, if Plesk recommends applying a critical security update as soon as possible, we will do so. The problem is what comes after applying the update.

As system administrators, we need to know what vulnerability we are dealing with. Without any technical information about the security issue, it is impossible to determine whether a server may have been exposed or compromised before the patch was installed.

We don't necessarily need a PoC or information that could facilitate exploitation before most systems have been patched. But we do need, at a minimum, enough information to understand the nature and impact of the vulnerability: affected component, attack vector, whether authentication is required, required privileges, possible impact, affected versions and, when available, the corresponding CVE.

Most importantly, we need to know what should be reviewed on systems that were running a vulnerable version.

Installing the patch prevents future exploitation, but it does not tell us whether the vulnerability was already exploited.

If this is considered a critical security issue, administrators need enough information to answer two different questions:
  1. Is my server protected now?
  2. Was my server compromised before I installed the update?
Update 4 allows us to answer the first question by installing it. With the information currently published, we have no way to answer the second.

I understand that some technical details may need to remain temporarily undisclosed while customers update their systems. However, there should be a security advisory providing administrators with actionable information as soon as reasonably possible.

"Critical security issue" alone is simply not enough information to properly manage a production server.

Regards,

Fede,
 
With this information "But we do need, at a minimum, enough information to understand the nature and impact of the vulnerability: affected component, attack vector, whether authentication is required, required privileges, possible impact, affected versions and, when available, the corresponding CVE." put out it is only a blink of an eye someone came up with a exploit and sets the hard working administrators under more pressure. there are companies that have more than one server to update...
 
Back
Top