Plesk vulnerabilities
CVEs whose affected-version data names the Plesk package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-68488Critical· 9.9A Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk causes local privilege escalation to root via arbitrary file/directory ownership takeover.
A Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk causes local privilege escalation to root via arbitrary file/directory ownership takeover.
▾ MidnightWebPros · PleskEPSS 0.23%via NVD
CVE-2026-68487Critical· 9.9Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.
Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.
▾ MidnightWebPros · PleskEPSS 0.41%via CVEORG
CVE-2026-65646Critical· 9.9Improper neutralization of special elements in in Plesk's DNS zone management functionality allows remote authenticated users to disclose arbitrary local files and escalate privileges.
Improper neutralization of special elements in in Plesk's DNS zone management functionality allows remote authenticated users to disclose arbitrary local files and escalate privileges.
▾ MidnightWebPros · PleskEPSS 0.39%via CVEORG