Our takeCanadian Cyber Centre warns of a blind SQL injection (CVE-2026-58046) in Plesk's XML-RPC API, fixed in 18.0.79.4. Patch now if you run Plesk.Cyber Resilience desk
What this means for you — Security leader:Update Plesk hosts to 18.0.79.4 or later to close CVE-2026-58046 blind SQL injection in the XML-RPC API.
What this means for you — Lean IT orgs:If you run your own Plesk server, update it to version 18.0.79.4 or newer as soon as possible.
What this means for you — MSP:Check all managed Plesk instances and update any still on versions before 18.0.79.4 to close CVE-2026-58046.
What this means for you — Researcher:Update Plesk hosts to 18.0.79.4 or later to close CVE-2026-58046 blind SQL injection in the XML-RPC API.