Our takeWebPros advisory AV26-790 confirms a blind SQL injection (CVE-2026-64636) in Plesk Obsidian before 18.0.80.1 and 18.0.79.5. Patch now if you run it yourself.Cyber Resilience desk
Sources (1)
- cccs · cccs
What this means for you — Security leader:Apply the WebPros patches to reach Plesk Obsidian 18.0.80.1 or 18.0.79.5. Blind SQL injection in a hosting control panel is high risk if your instances are internet-facing.
What this means for you — Lean IT orgs:If you run your own Plesk server, update it immediately to version 18.0.80.1 or 18.0.79.5. Most lean-IT teams use hosted services and can ignore this.
What this means for you — MSP:Check every client Plesk Obsidian instance; patch to 18.0.80.1 or 18.0.79.5. Prioritize any exposed to the internet.
What this means for you — Researcher:WebPros confirmed blind SQL injection (CVE-2026-64636) in Plesk Obsidian prior to 18.0.80.1 and 18.0.79.5. Patch or upgrade.