ThreatCluster

Critical Plesk Vulnerability Allows Arbitrary Command Execution

First seen 1 Jun 2026, 21:22 UTC CybersecuritynewsGbhackers 96% similarity 71

Article Content

Browse articles
ThreatCluster

A critical vulnerability in Plesk, tracked as CVE-2026-44962, was disclosed on May 29, 2026. This flaw enables authenticated low-privileged users to execute arbitrary operating system commands on affected servers. The vulnerability is linked to improper input handling in the APS Application Catalog component of Plesk for Linux. Security researchers have raised alarms about the potential for exploitation, which could lead to significant impacts on server integrity and data security. The issue has been documented in both the National Vulnerability Database and GitHub Advisory Database. Administrators are urged to assess their systems for this vulnerability and apply necessary mitigations. The scope of impact includes all versions of Plesk that utilize the affected component.

Key Points: • CVE-2026-44962 allows low-privileged users to execute arbitrary commands on Plesk servers. • The vulnerability is linked to improper input handling in the APS Application Catalog. • Affected systems include all versions of Plesk for Linux utilizing the vulnerable component.

ThreatCluster AI

Timeline

2026-05-29
CVE-2026-44962 published
A critical vulnerability in Plesk was disclosed, allowing command execution by low-privileged users.
Cybersecuritynews
2026-06-01
Security concerns raised
Researchers confirmed the vulnerability's potential for exploitation, urging immediate attention from administrators.
Gbhackers

Community

Browse all →

Tracked Entities in This Story