Cyber Centre Daily Advisory Digest — 2026-08-27 (3 advisories)
The Canadian Centre for Cyber Security published three security advisories on 2026-08-27 covering vulnerabilities in SonicWall NetExtender Linux Client, WebPros Plesk and associated extensions, and Veeam Backup and Replication plus Veeam ONE. Two CVEs are explicitly identified for Plesk (CVE-2026-65642 and CVE-2026-65647). The advisories recommend reviewing vendor publications and applying updates as they become available.
- cveCVE-2026-65642Vulnerability in Plesk's database management interface; specific exploit details not provided in the advisory.
- cveCVE-2026-65647Vulnerability in Plesk's Site Import and Migrator extensions; specific exploit details not provided in the advisory.
Detection / Hunteropenrouter
What Happened
A Canadian government cybersecurity agency published three alerts on August 27, 2026 about security flaws in software from three companies: SonicWall, WebPros (maker of Plesk), and Veeam. These flaws could affect organizations using the listed products. Administrators and users of these products should check the vendor websites for patches and apply them promptly to reduce risk of compromise.
Key Takeaways
- SonicWall NetExtender Linux Client versions 3.5 and earlier are affected by vulnerabilities; updates should be applied as they become available.
- WebPros Plesk, Plesk Migrator, and Plesk Site Import have vulnerabilities tracked as CVE-2026-65642 and CVE-2026-65647 in the database management and Site Import/Migrator extensions respectively.
- Veeam Backup and Replication (prior to 13.0.3 build 13.0.3.63 and prior to 13.1 build 13.1.0.411) and Veeam ONE (prior to or equal to 13.0.2.6723 and 13.1.0.7034) are affected by vulnerabilities; patches are referenced in KB4902 and KB4905.
Affected Systems
- SonicWall NetExtender Linux Client 3.5 and earlier versions
- WebPros Plesk prior to 18.0.79.8 and prior to 18.0.80.4
- WebPros Plesk Migrator prior to 2.36.0
- WebPros Plesk Site Import prior to 1.12.1
- Veeam Backup and Replication prior to 13.0.3 (build 13.0.3.63) and prior to 13.1 (build 13.1.0.411)
- Veeam ONE prior to or equal to 13.0.2.6723 and prior to or equal to 13.1.0.7034
Vulnerabilities (CVEs)
| CVE | Product | Severity | Description |
|---|---|---|---|
| CVE-2026-65642 | WebPros Plesk database management interface | Vulnerability in Plesk's database management interface; specific exploit details not provided in the advisory. | |
| CVE-2026-65647 | WebPros Plesk Site Import and Migrator extensions | Vulnerability in Plesk's Site Import and Migrator extensions; specific exploit details not provided in the advisory. |
Detection Availability
- YARA Rules: No
- Sigma Rules: No
- Snort/Suricata Rules: No
- KQL Queries: No
- Splunk SPL Queries: No
- EQL Queries: No
- Other Detection Logic: No
No detection rules or queries are provided in the advisory digest. The advisories reference vendor security advisories and knowledge base articles for patch information.
Detection Engineering Assessment
| Dimension | Rating | Rationale |
|---|---|---|
| EDR Visibility | None | The advisories do not describe specific exploitation techniques or post-exploitation behavior that would generate EDR-detectable telemetry. |
| Network Visibility | None | No network-based indicators or exploitation patterns are described in the advisories. |
| Detection Difficulty | Easy | Detection in this context is limited to identifying vulnerable software versions in the environment. No behavioral detection is possible from the advisory text alone. |
Required Log Sources
- Vendor advisory feeds
- Asset inventory and software version data
Hunting Hypotheses
| Hypothesis | Telemetry | ATT&CK Stage | FP Risk |
|---|---|---|---|
| Consider identifying all instances of SonicWall NetExtender Linux Client, Plesk, Plesk Migrator, Plesk Site Import, Veeam Backup and Replication, and Veeam ONE in the environment to determine which are running vulnerable versions. | Asset inventory, software management platform, or CMDB data | Vulnerability Management | Low — version identification is deterministic. |
Control Gaps
- Organizations without centralized asset inventory may not know which systems run the affected products or versions.
Key Behavioral Indicators
- Presence of SonicWall NetExtender Linux Client version 3.5 or earlier
- Presence of Plesk versions prior to 18.0.79.8 or 18.0.80.4
- Presence of Veeam Backup and Replication builds prior to 13.0.3.63 or 13.1.0.411
- Presence of Veeam ONE builds 13.0.2.6723 or earlier, or 13.1.0.7034 or earlier
False Positive Assessment
Low — the advisories reference specific product versions; identifying vulnerable instances is a deterministic version-matching exercise.
Recommendations
Immediate Mitigation
- Verify against your organization's incident response runbook and team escalation paths before acting. Consider inventorying all systems running SonicWall NetExtender Linux Client, Plesk and its extensions, and Veeam Backup and Replication or Veeam ONE to identify vulnerable versions.
- Consider reviewing the SonicWall security advisory page and applying updates for NetExtender Linux Client as they become available.
- Consider reviewing the WebPros Plesk advisory and applying updates to Plesk (18.0.79.8 or 18.0.80.4 or later), Plesk Migrator (2.36.0 or later), and Plesk Site Import (1.12.1 or later).
- Consider reviewing Veeam KB4902 and KB4905 and applying patches for Veeam Backup and Replication (13.0.3 build 13.0.3.63 or 13.1 build 13.1.0.411 or later) and Veeam ONE (versions newer than 13.0.2.6723 and 13.1.0.7034).
Infrastructure Hardening
- Consider restricting network access to Plesk, Veeam Backup and Replication, and Veeam ONE management interfaces to trusted administrative networks only.
- Evaluate whether temporary access restrictions or compensating controls can be applied to affected systems until patches are deployed.
User Protection
- If SonicWall NetExtender Linux Client is deployed to remote users, consider notifying affected users to update their client software when patches are available.
Security Awareness
- Consider incorporating these advisories into existing vulnerability management and patching communication channels to ensure timely awareness among system administrators.