The Canadian Centre for Cyber Security published an advisory indicating that WebPros Plesk versions prior to 18.0.79.9 and 18.0.80.5 are affected by a privilege escalation vulnerability tracked as CVE-2026-67394. The vulnerability allows an attacker to escalate privileges to root on the Plesk server. Administrators are encouraged to review the advisory and apply updates when available.
plesk
3 posts
Cyber Centre Daily Advisory Digest — 2026-09-01 (1 advisories) Cyber Centre Daily Advisory Digest — 2026-08-27 (3 advisories) The Canadian Centre for Cyber Security published three security advisories on 2026-08-27 covering vulnerabilities in SonicWall NetExtender Linux Client, WebPros Plesk and associated extensions, and Veeam Backup and Replication plus Veeam ONE. Two CVEs are explicitly identified for Plesk (CVE-2026-65642 and CVE-2026-65647). The advisories recommend reviewing vendor publications and applying updates as they become available.
Cyber Centre Daily Advisory Digest — 2026-08-13 (4 advisories) The Canadian Centre for Cyber Security published four security advisories on August 13, 2026. The most critical is CVE-2026-20349, a high-severity denial-of-service vulnerability in Cisco ASA and FTD SSL VPN services that is being actively exploited in the wild. Additional advisories cover vulnerabilities in AMD software, GitLab, and WebPros Plesk, the latter involving a privilege escalation flaw via database cloning.