Critical Plesk Vulnerability Allows Arbitrary Command Execution
Article Content
- •CVE-2026-44962 allows low-privileged users to execute arbitrary commands on Plesk servers.
- •The vulnerability is linked to improper input handling in the APS Application Catalog.
- •Affected systems include all versions of Plesk for Linux utilizing the vulnerable component.
A critical vulnerability in Plesk, tracked as CVE-2026-44962, was disclosed on May 29, 2026. This flaw enables authenticated low-privileged users to execute arbitrary operating system commands on affected servers. The vulnerability is linked to improper input handling in the APS Application Catalog component of Plesk for Linux. Security researchers have raised alarms about the potential for exploitation, which could lead to significant impacts on server integrity and data security. The issue has been documented in both the National Vulnerability Database and GitHub Advisory Database. Administrators are urged to assess their systems for this vulnerability and apply necessary mitigations. The scope of impact includes all versions of Plesk that utilize the affected component.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-44962 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…