Fede Marsell
Basic Pleskian
- Server operating system version
- AlmaLinux 8
- Plesk version and microupdate number
- 18.0.80#4
Hello,
I don't think the current way of communicating critical security updates is sufficient for system administrators.
For Plesk Obsidian 18.0.80 Update 4, the only information currently available is:
Of course, if Plesk recommends applying a critical security update as soon as possible, we will do so. The problem is what comes after applying the update.
As system administrators, we need to know what vulnerability we are dealing with. Without any technical information about the security issue, it is impossible to determine whether a server may have been exposed or compromised before the patch was installed.
We don't necessarily need a PoC or information that could facilitate exploitation before most systems have been patched. But we do need, at a minimum, enough information to understand the nature and impact of the vulnerability: affected component, attack vector, whether authentication is required, required privileges, possible impact, affected versions and, when available, the corresponding CVE.
Most importantly, we need to know what should be reviewed on systems that were running a vulnerable version.
Installing the patch prevents future exploitation, but it does not tell us whether the vulnerability was already exploited.
If this is considered a critical security issue, administrators need enough information to answer two different questions:
I understand that some technical details may need to remain temporarily undisclosed while customers update their systems. However, there should be a security advisory providing administrators with actionable information as soon as reasonably possible.
"Critical security issue" alone is simply not enough information to properly manage a production server.
Regards,
Fede,
I don't think the current way of communicating critical security updates is sufficient for system administrators.
For Plesk Obsidian 18.0.80 Update 4, the only information currently available is:
Plesk Obsidian 18.0.80 Update 4 — 24 August 2026
This update addresses a critical security issue. We strongly recommend that you apply it as soon as possible.
Note: More details to follow shortly.
Of course, if Plesk recommends applying a critical security update as soon as possible, we will do so. The problem is what comes after applying the update.
As system administrators, we need to know what vulnerability we are dealing with. Without any technical information about the security issue, it is impossible to determine whether a server may have been exposed or compromised before the patch was installed.
We don't necessarily need a PoC or information that could facilitate exploitation before most systems have been patched. But we do need, at a minimum, enough information to understand the nature and impact of the vulnerability: affected component, attack vector, whether authentication is required, required privileges, possible impact, affected versions and, when available, the corresponding CVE.
Most importantly, we need to know what should be reviewed on systems that were running a vulnerable version.
Installing the patch prevents future exploitation, but it does not tell us whether the vulnerability was already exploited.
If this is considered a critical security issue, administrators need enough information to answer two different questions:
- Is my server protected now?
- Was my server compromised before I installed the update?
I understand that some technical details may need to remain temporarily undisclosed while customers update their systems. However, there should be a security advisory providing administrators with actionable information as soon as reasonably possible.
"Critical security issue" alone is simply not enough information to properly manage a production server.
Regards,
Fede,