ThreatCluster

Critical Privilege Escalation Vulnerability in Plesk Requires Immediate Action

First seen 14 Aug 2026, 06:35 UTC Ccb.Belgium.Bewww.tenable.comsupport.plesk.com 79% similarity 72

Article Content

Browse articles
ThreatCluster

A severe privilege escalation vulnerability, CVE-2026-64639, has been identified in Plesk versions prior to 18.0.79.6 and 18.0.80.2. This flaw allows low-privileged users to execute arbitrary code as the database server administrator, significantly impacting multi-tenant hosting environments. The vulnerability was published on August 12, 2026, and has a CVSS score of 9.3, indicating a high severity level. While there is currently no evidence of exploitation in the wild, the Centre for Cybersecurity Belgium has issued an urgent recommendation for affected organizations to apply patches immediately. The vulnerability affects users who can clone or copy databases, potentially allowing them to breach intended security boundaries. Organizations are advised to enhance monitoring and detection capabilities to identify any suspicious activity related to this vulnerability.

Key Points: • CVE-2026-64639 allows low-privileged users to escalate privileges on Plesk servers. • The vulnerability has a high CVSS score of 9.3, indicating critical risk. • Immediate patching is recommended as there is currently no known exploitation.

ThreatCluster AI How this analysis works

Timeline

2026-08-12
CVE-2026-64639 published
A privilege escalation vulnerability in Plesk was disclosed, affecting multiple versions.
www.tenable.com
2026-08-13
CCB issues urgent patch recommendation
The Centre for Cybersecurity Belgium advised immediate patching for vulnerable Plesk installations.
Ccb.Belgium.Be

Community

Browse all →

Tracked Entities in This Story