Hangover2
Regular Pleskian
Somehow, it isn’t funny anymore. I just received the following email:
"[Important] Plesk Security Advisory: Patch Arriving on 27th August 2026"
We have now counted at least six emergency security patch releases within 30 days.
Perhaps it is time for Plesk to tell its users what is going on. Has the Plesk source code been compromised or leaked? Or is there another explanation for why a closed-source project has experienced this level of security problems for four consecutive weeks?
At this point, Plesk users deserve a transparent explanation.
"[Important] Plesk Security Advisory: Patch Arriving on 27th August 2026"
Dear Customer,
We are writing to let you know that a Plesk security patch is expected to be released on 27th August, 2026.
This release addresses a vulnerability across versions of Plesk, including fixes for vulnerability rated up to critical severity.
Technical details and support articles will be made available following patch release to help limit further exposure.
Affected Versions:
Patch:
- Plesk for Linux 18.0.34 - 18.0.79.8
- Plesk for Linux 18.0.80 - 18.0.80.4
The patch will be distributed through the standard Plesk automatic update process and through the manual update process. We strongly recommend performing a manual update once the patch is made available.
Prepare Now
We will follow up the moment the patch is live with full details and remediation steps.
- Identify affected servers. Review your servers on the affected versions above.
- Brief your team. If your environment requires a maintenance window, notify the relevant people so they are ready to act.
- Watch for a follow-up email with exact patched versions and a link to all technical details in the support article.
Please reach out to our suport team if you have any questions or need further guidance.
Best Regards,
Your Plesk Team
We have now counted at least six emergency security patch releases within 30 days.
Perhaps it is time for Plesk to tell its users what is going on. Has the Plesk source code been compromised or leaked? Or is there another explanation for why a closed-source project has experienced this level of security problems for four consecutive weeks?
At this point, Plesk users deserve a transparent explanation.