• Debian 11 is approaching its end-of-life (vendor EOL date - August 31, 2026). Plesk Obsidian 18.0.80 will be the last release to support it.
    If you are running Plesk Obsidian on Debian 11, we recommend you upgrade those servers to Debian 12 using our dist-upgrade tool.
  • We plan to deprecate and remove the support for XML RPC protocol versions earlier than 1.6.9.1 in Plesk Obsidian 18.0.82. We strongly recommend that you update all existing integrations using earlier versions of the XML RPC protocol to comply with the version 1.6.9.1 specification.

Question [Important] Plesk Security Advisory: Patch Arriving on 27th August 2026

Hangover2

Regular Pleskian
Somehow, it isn’t funny anymore. I just received the following email:

"[Important] Plesk Security Advisory: Patch Arriving on 27th August 2026"
Dear Customer,

We are writing to let you know that a Plesk security patch is expected to be released on 27th August, 2026.

This release addresses a vulnerability across versions of Plesk, including fixes for vulnerability rated up to critical severity.

Technical details and support articles will be made available following patch release to help limit further exposure.

Affected Versions:
  • Plesk for Linux 18.0.34 - 18.0.79.8
  • Plesk for Linux 18.0.80 - 18.0.80.4
Patch:
The patch will be distributed through the standard Plesk automatic update process and through the manual update process. We strongly recommend performing a manual update once the patch is made available.


Prepare Now
  • Identify affected servers. Review your servers on the affected versions above.
  • Brief your team. If your environment requires a maintenance window, notify the relevant people so they are ready to act.
  • Watch for a follow-up email with exact patched versions and a link to all technical details in the support article.
We will follow up the moment the patch is live with full details and remediation steps.

Please reach out to our suport team if you have any questions or need further guidance.


Best Regards,
Your Plesk Team

We have now counted at least six emergency security patch releases within 30 days.

Perhaps it is time for Plesk to tell its users what is going on. Has the Plesk source code been compromised or leaked? Or is there another explanation for why a closed-source project has experienced this level of security problems for four consecutive weeks?

At this point, Plesk users deserve a transparent explanation.
 
At this point, Plesk users deserve a transparent explanation.
I don't quite get the criticism here. Really, what is there to explain? Would you rather Plesk did not release that many security updates?

The number of consecutive patches over the past few weeks is certainly unfortunate, but I for one am quite happy that security issues are being fixed as soon as vulnerabilities are identified. No matter how time-consuming or annoying it is to manually patch a bunch of servers, I would much rather deal with several separate security patches than have to wait for a bundled update containing multiple fixes. (Unfortunately, delaying fixes in order to bundle them into a larger release is not exactly uncommon among software vendors).

I also don't think the number or timing of these patches, by itself, is evidence that something unusual has happened such as Plesk's source code being compromised or leaked.

Vulnerabilities are often discovered in clusters. Once a security researcher starts looking closely at a particular product or component, finding one vulnerability can quite naturally lead to finding several more. In fact, several of the recent Plesk vulnerabilities were reported by the same researcher. That doesn't necessarily mean Plesk suddenly became less secure; some of those vulnerabilities may simply have existed for some time and are being discovered now.

Plesk is also a very large and complex product with a considerable attack surface. It manages websites, databases, DNS, mail, system users, backups and many other services, often with elevated privileges. The fact that it is closed source doesn't prevent researchers or attackers from finding vulnerabilities either.

Where I do agree there is room for improvement is communication. The information surrounding the recent Migrator vulnerability in particular has been disappointing. Server administrators need enough information to understand their exposure and how to mitigate a vulnerability. That said, I do think the team has picked up on previous community feedback, and I am happy to see that many of the suggestions and requests regarding security communication are now being implemented.

Edit: just wanted to add that some (1) (2) (3) (4) of the recent vulnerability where disclosed trough Plesk bug bounty program CVD.
 
Last edited:
One needs to live in an bubble, to not have seen or felt the ripple that Fable/Mythos 5 and the likes have had on many software projects in past couple weeks.
Just yesterday did Google release a Chrome update that patched ~340 new security vulnerabilities, most of them found by AI. (on top of the thousand+ vulnerabilities, that were already found and patched in the weeks before)

And that is just one example of many...think about nginx, keycloak, joomla, wordpress, vmware and many more projects, that all had multiple extremely critical security flaws with CVE scores of 9.x to 10 in the last 1-2 months.

I'm pretty sure that some security researchers or Plesk itself, is currently scanning the whole panel code base with the help of Fable or Mythos.
And all these patches and security advisories we are seeing now, are the result of that process.
 
@Kaspar and @ChristophRo are essentially right, and honestly, they're doing the job that Plesk itself should be doing.

Plesk never explains why so many security issues are suddenly surfacing. They don't say whether these vulnerabilities were found internally through their own auditing, whether they've already been fixed quietly, or whether there is any evidence of active exploitation in the wild. Plesk has access to exactly this kind of data - through support tickets, telemetry, and server monitoring - yet none of it is shared with users. It is also positive that Plesk is addressing the issues and notifying customers before the patch is released.

My concern is mainly about the quality and context of the communication.

The latest announcement says that a patch is expected on 27 August 2026 and that it will address vulnerabilities rated up to critical severity. It also asks administrators to identify affected servers, prepare their teams, and perform a manual update once the patch becomes available. Those recommendations are reasonable, particularly for environments that require a maintenance window.

However, the announcement provides very little information about the situation itself. Until the patch is released, customers are not told the exact vulnerability, its practical impact, whether there is evidence of active exploitation, or whether the issue was discovered internally, through the bug-bounty programme, or by an external researcher. I understand that technical details may need to remain confidential until a fix is available, but even a general indication of the risk and the reason for the advance warning would help administrators assess the situation more accurately.

After several security advisories in a relatively short period, this lack of context can make the messages feel more alarming than they may actually be. Plesk does not necessarily need to disclose sensitive technical details before the patch is ready, but it should communicate more clearly about the nature of the risk, the urgency of the update, and whether any exploitation is currently known.

The issue, therefore, is not that Plesk is releasing security patches or warning customers in advance. Those are positive actions. The issue is that repeated high-severity announcements, combined with limited context before release, make it difficult for users to distinguish between a precautionary disclosure and an active emergency.

Greater transparency and more measured wording would help Plesk users respond appropriately without either underestimating or overstating the risk.

Now it feels like: have your whole team on stand-by, sth. big is coming, vacation blackout period...
 
It wasn't my intention to answer for Plesk, I was merely surprised by your criticism, as (to me) it felt you criticized the recent number of security fixes. But it seems I might have gotten you post wrong.

I think we're mostly disagreeing about how much explanation Plesk can reasonably be expected to provide here. I don't really think Plesk owes us an additional explanation regarding why there are so many vulnerabilities have surfaced recently. Sure, if the code base got comprised I'd like to know. And if a vulnerability gets actively exploited I sure like you know too. But otherwise, what does it matter where the vulnerabilities originated from?

To some extent, there already is an implicitly explanation. A good number of the recent vulnerabilities are credited in the support articles to the same security researcher, Aziz Knani, who responsibly disclosed them to Plesk. That seems like a fairly mundane explanation for at least part of the recent increase: somebody has been actively researching Plesk, found several vulnerabilities and reported them. I don't think there necessarily needs to be a bigger story behind it.

As for the amount of information in the advance warning, I do understand your point. As an administrator, of course I would like to know exactly what component is affected, what the prerequisites for exploitation are, what the practical impact is, and whether exploitation has been observed.

But there is always going to be tension between providing that information and giving administrators sufficient time to patch before potentially useful information is made public. Even fairly high-level information about the affected component, required privileges and practical impact can considerably narrow down where someone needs to look for the vulnerability. If the patch isn't available yet, every Plesk server is still vulnerable at that point. I can therefore understand why Plesk deliberately keeps the pre-release announcement fairly generic and releases the technical information together with the fix. I actually think Plesk is doing a pretty good job of balancing those interests with this particular announcement.

That's not to say there isn't room for improvement. I could see value in making it clearer in these advance notices whether "critical" simply refers to the severity rating or whether there is some additional reason for urgency, such as known exploitation. The communication surrounding the recent Migrator vulnerability is a good example where I think Plesk could have done considerably better I my option. As this vulnerability wasn't (and still isn't) communicated in the change log nor was there a security mailing send out.
 
@Plesk Team: 2nd question: Could you clarify whether the Phusion Passenger server needs to be installed to be affected by this vulnerability? It was updated with the latest patch release.
 
Back
Top