We would like to inform you of two recently disclosed security vulnerabilities affecting multiple versions of Plesk Control Panel. Security hotfixes have been released by Plesk, and we strongly recommend updating your server at the earliest opportunity to protect your environment.
Affected Vulnerabilities
CVE
Description
CVE-2026-64636
Blind SQL Injection
An authenticated attacker could potentially extract information from the server database using a read-only SQL injection vulnerability.
Affected Versions: Plesk 18.0.51 through 18.0.79.4