Panellicense

Plesk CVE-2026-65646, 65642, and 65647: patch your server

Three critical Plesk flaws expose server files, customer databases, and root access. Check the affected builds and update Plesk plus both extensions.

pleskcvesecuritydnsdatabasemigrator
schema: TechArticleschema: FAQPageschema: BreadcrumbList

Plesk has released fixes for three critical vulnerabilities: CVE-2026-65646, CVE-2026-65642, and CVE-2026-65647. Two require a Plesk microupdate. The third requires separate updates for Plesk Migrator and Site Import.

A server can have the patched Plesk build and still remain vulnerable through the extensions. Check all three versions rather than stopping after plesk version reports a current build.

What the vulnerabilities expose

CVEComponentImpact
CVE-2026-65646DNS zone managementA customer with a DNS-managed domain can read arbitrary server files and recover Plesk administrator and database credentials.
CVE-2026-65642Database management interfaceAn authenticated user can read, modify, or delete databases owned by other Plesk users.
CVE-2026-65647Plesk Migrator and Site ImportAn unprivileged user can execute arbitrary code as root.

These flaws matter most on multi-tenant servers. A normal customer account is enough to reach the affected paths; the attacker does not need an existing administrator login.

Affected and patched versions

ComponentAffectedPatched
Plesk for Linux 18.0.7918.0.79.7 and earlier18.0.79.8
Plesk for Linux 18.0.8018.0.80 through 18.0.80.318.0.80.4
Plesk Migrator2.35.0 and earlier2.36.0
Site Import1.12.0 and earlier1.12.1

If your server runs an older Plesk branch, update to a supported patched build. Keeping a current Plesk license ensures the server remains eligible for vendor microupdates.

Check the installed versions

Run the following as root:

plesk version

for ext in panel-migrator site-import; do
  version=$(grep -oPm1 '(?<=<version>)[^<]+' "/usr/local/psa/admin/plib/modules/$ext/meta.xml")
  printf '%-16s %s\n' "$ext" "$version"
done

Safe output must show either Plesk 18.0.79.8 or 18.0.80.4, Plesk Migrator 2.36.0 or later, and Site Import 1.12.1 or later. The Plesk 18.0.79 release notes cover the wider changes in that branch.

Install the fixes

Take a current server backup, then install the latest Plesk microupdate from Tools & Settings > Updates and Upgrades. Update both extensions separately:

plesk bin extension --upgrade panel-migrator
plesk bin extension --upgrade site-import

Run the version checks again after the upgrade. Do not treat an updated core as proof that the extensions were updated; Plesk distributes them through separate channels.

Restricting customer access is not a durable substitute for patching. Firewall rules can reduce exposure around the panel, as described in the Plesk Firewall setup guide, but these flaws are reachable by authorised low-privilege users.

Which Plesk version fixes CVE-2026-65646 and CVE-2026-65642?+
Use Plesk for Linux 18.0.79.8 or 18.0.80.4. Earlier builds in those branches are affected.
Does updating Plesk also fix CVE-2026-65647?+
No. Update Plesk Migrator to 2.36.0 and Site Import to 1.12.1 separately, then verify both installed versions.
Can I uninstall Plesk Migrator and Site Import instead?+
Yes, removing an unused affected extension removes that extension's attack surface. If you need either extension, install its patched version instead.

Next steps

how to
Configure Plesk Fail2Ban jails to stop brute-force attacks
Enable Plesk's Fail2Ban, tune the default jails, whitelist your own IPs, and fix the silent failures where bans show in the panel but never reach iptables.
7 min read
how to
Set up the Plesk Firewall extension without locking yourself out
Enable the Plesk Firewall extension, open the right ports, write custom allow/deny rules by IP and country, and use the 60-second rollback so a bad rule never strands you.
7 min read
how to
Set up secondary DNS for Plesk with Slave DNS Manager
A Plesk box serving its own DNS is a single point of failure. Wire up a plain BIND server as a secondary nameserver with the Slave DNS Manager extension.
8 min read
changelog
RtabRace (CVE-2026-68138): mitigating the kernel race on CloudLinux
A traffic-control race in the Linux kernel lets any shell user panic a shared server on demand. CloudLinux 8 and 7 Hybrid need the sysctl mitigation today — here's the command and the patch status.
5 min read
changelog
CVE-2026-33278: the cpanel-unbound DNSSEC RCE, and how to check for it
A critical Unbound DNSSEC validator bug shipped as cpanel-unbound puts remote code execution one malicious signed zone away, no login required. Patched builds and how to check exposure.
7 min read
changelog
EasyApache 4 25.69: cPanel patches six Tomcat CVEs in ea-tomcat101
EasyApache 4 25.69 ships Apache Tomcat 10.1.56 in ea-tomcat101, closing six CVEs — an auth-bypass on default servlet constraints among them. Here's what's fixed and how to update.
5 min read
Switch in an afternoon

Switch from your current reseller — free.

We migrate active cPanel, Plesk, LiteSpeed and CloudLinux licenses from any reseller. We prorate the first month so you never pay twice, and your customers see zero downtime during the swap.