[Important] Plesk Security Advisory: Two Critical Vulnerabilities identified, Hotfix Available - Action Required

  • Friday, 7th August, 2026
  • 10:22am

 

⚠ Important Security Advisory

Critical Plesk Security Vulnerabilities – Immediate Action Required

Dear Customer,

We would like to inform you of two recently disclosed security vulnerabilities affecting multiple versions of Plesk Control Panel. Security hotfixes have been released by Plesk, and we strongly recommend updating your server at the earliest opportunity to protect your environment.


Affected Vulnerabilities

CVE Description
CVE-2026-64636 Blind SQL Injection

An authenticated attacker could potentially extract information from the server database using a read-only SQL injection vulnerability.

Affected Versions:
Plesk 18.0.51 through 18.0.79.4

Fixed In:
18.0.79.5 and 18.0.80.1

Support Article:
https://support.plesk.com/hc/en-us/articles/42431868205079
CVE-2026-64637 Reseller Privilege Escalation to Root

An attacker with Reseller-level access could escalate privileges and gain Root-level access to the server.

Affected Versions:
All Plesk versions prior to 18.0.79.5

Fixed In:
18.0.79.5 and 18.0.80.1

Support Article:
https://support.plesk.com/hc/en-us/articles/42432168683799

Immediate Action Required

If your server is running an affected version of Plesk, please install the latest updates immediately.

  1. Log in to your Plesk Control Panel using the Administrator or Root account.
  2. Navigate to Tools & Settings → Updates and Upgrades.
  3. Install all available updates.
  4. Ensure your server is upgraded to Plesk 18.0.79.5 or later (recommended: 18.0.80.1).
  5. Verify the installed version under Tools & Settings → Server Components.
Temporary Mitigation (Only if Immediate Update Is Not Possible)

You can temporarily reduce exposure by implementing one or both of the following measures:
  • Disable OS-level system logins for reseller accounts by setting systemAdmin = off under the [login] section of Panel.ini.
  • Disable API access for reseller accounts through the appropriate Service Plan permissions.
Please note that these are temporary mitigations only and do not replace installing the official security update.
We strongly recommend upgrading to the latest Plesk hotfix version as soon as possible to ensure your server remains secure.

If you require any assistance with updating your server, please feel free to contact our support team.

Kind Regards,

SysopHost Support Team
Technical Support

This is an important security notification regarding your hosting services. Please do not ignore this advisory.

```

« Back