Our takeWebPros advisory AV26-854 covers vulnerabilities in Plesk (before 18.0.79.8 and 18.0.80.4), Plesk Migrator (before 2.36.0), and Plesk Site Import (before 1.12.1). Patch now if you run them.Cyber Resilience desk
Sources (1)
- cccs · cccs
What this means for you — Security leader:WebPros advisory AV26-854 confirms vulnerabilities in Plesk (prior to 18.0.79.8 or 18.0.80.4), Plesk Migrator (prior to 2.36.0) and Plesk Site Import (prior to 1.12.1). Update immediately if you self-host any of these.
What this means for you — Lean IT orgs:If you run Plesk on your own server, update it to at least 18.0.79.8 or 18.0.80.4, and update Plesk Migrator to 2.36.0 and Site Import to 1.12.1. Most teams without a server can ignore this.
What this means for you — MSP:Check every client Plesk instance for versions prior to 18.0.79.8/18.0.80.4 (core), 2.36.0 (Migrator) or 1.12.1 (Site Import) and patch immediately.
What this means for you — Researcher:WebPros advisory AV26-854 confirms vulnerabilities in Plesk before 18.0.79.8/18.0.80.4, Plesk Migrator before 2.36.0 and Plesk Site Import before 1.12.1. Patch now if you run it yourself.