• Debian 11 is approaching its end-of-life (vendor EOL date - August 31, 2026). Plesk Obsidian 18.0.80 will be the last release to support it.
    If you are running Plesk Obsidian on Debian 11, we recommend you upgrade those servers to Debian 12 using our dist-upgrade tool.
  • We plan to deprecate and remove the support for XML RPC protocol versions earlier than 1.6.9.1 in Plesk Obsidian 18.0.82. We strongly recommend that you update all existing integrations using earlier versions of the XML RPC protocol to comply with the version 1.6.9.1 specification.

Question [Important] Plesk Security Advisory: Patch Arriving on 27th August 2026

Hangover2

Regular Pleskian
Somehow, it isn’t funny anymore. I just received the following email:

"[Important] Plesk Security Advisory: Patch Arriving on 27th August 2026"
Dear Customer,

We are writing to let you know that a Plesk security patch is expected to be released on 27th August, 2026.

This release addresses a vulnerability across versions of Plesk, including fixes for vulnerability rated up to critical severity.

Technical details and support articles will be made available following patch release to help limit further exposure.

Affected Versions:
  • Plesk for Linux 18.0.34 - 18.0.79.8
  • Plesk for Linux 18.0.80 - 18.0.80.4
Patch:
The patch will be distributed through the standard Plesk automatic update process and through the manual update process. We strongly recommend performing a manual update once the patch is made available.


Prepare Now
  • Identify affected servers. Review your servers on the affected versions above.
  • Brief your team. If your environment requires a maintenance window, notify the relevant people so they are ready to act.
  • Watch for a follow-up email with exact patched versions and a link to all technical details in the support article.
We will follow up the moment the patch is live with full details and remediation steps.

Please reach out to our suport team if you have any questions or need further guidance.


Best Regards,
Your Plesk Team

We have now counted at least six emergency security patch releases within 30 days.

Perhaps it is time for Plesk to tell its users what is going on. Has the Plesk source code been compromised or leaked? Or is there another explanation for why a closed-source project has experienced this level of security problems for four consecutive weeks?

At this point, Plesk users deserve a transparent explanation.
 
At this point, Plesk users deserve a transparent explanation.
I don't quite get the criticism here. Really, what is there to explain? Would you rather Plesk did not release that many security updates?

The number of consecutive patches over the past few weeks is certainly unfortunate, but I for one am quite happy that security issues are being fixed as soon as vulnerabilities are identified. No matter how time-consuming or annoying it is to manually patch a bunch of servers, I would much rather deal with several separate security patches than have to wait for a bundled update containing multiple fixes. (Unfortunately, delaying fixes in order to bundle them into a larger release is not exactly uncommon among software vendors).

I also don't think the number or timing of these patches, by itself, is evidence that something unusual has happened such as Plesk's source code being compromised or leaked.

Vulnerabilities are often discovered in clusters. Once a security researcher starts looking closely at a particular product or component, finding one vulnerability can quite naturally lead to finding several more. In fact, several of the recent Plesk vulnerabilities were reported by the same researcher. That doesn't necessarily mean Plesk suddenly became less secure; some of those vulnerabilities may simply have existed for some time and are being discovered now.

Plesk is also a very large and complex product with a considerable attack surface. It manages websites, databases, DNS, mail, system users, backups and many other services, often with elevated privileges. The fact that it is closed source doesn't prevent researchers or attackers from finding vulnerabilities either.

Where I do agree there is room for improvement is communication. The information surrounding the recent Migrator vulnerability in particular has been disappointing. Server administrators need enough information to understand their exposure and how to mitigate a vulnerability. That said, I do think the team has picked up on previous community feedback, and I am happy to see that many of the suggestions and requests regarding security communication are now being implemented.

Edit: just wanted to add that some (1) (2) (3) (4) of the recent vulnerability where disclosed trough Plesk bug bounty program.
 
Last edited:
One needs to live in an bubble, to not have seen or felt the ripple that Fable/Mythos 5 and the likes have had on many software projects in past couple weeks.
Just yesterday did Google release a Chrome update that patched ~340 new security vulnerabilities, most of them found by AI. (on top of the thousand+ vulnerabilities, that were already found and patched in the weeks before)

And that is just one example of many...think about nginx, keycloak, joomla, wordpress, vmware and many more projects, that all had multiple extremely critical security flaws with CVE scores of 9.x to 10 in the last 1-2 months.

I'm pretty sure that some security researchers or Plesk itself, is currently scanning the whole panel code base with the help of Fable or Mythos.
And all these patches and security advisories we are seeing now, are the result of that process.
 
Back
Top