Liquid Web incident

Security vulnerability CVE-2026-87898 on Plesk's Site Import extension

Notice Resolved View vendor source →

Liquid Web experienced a notice incident on September 26, 2026 affecting Plesk, lasting 11h 40m. The incident has been resolved; the full update timeline is below.

Started
Sep 26, 2026, 03:10 PM UTC
Resolved
Sep 27, 2026, 02:50 AM UTC
Duration
11h 40m
Detected by Pingoru
Sep 26, 2026, 03:10 PM UTC

Affected components

Plesk

Update timeline

  1. investigating Sep 26, 2026, 03:10 PM UTC

    We have identified a security vulnerability CVE-2026-87898 in the Plesk Site Import extension on Linux servers. This issue involves improper sanitization of database names during imports, which could allow unauthorized command execution with root privileges. Affected product version: Plesk for Linux: 1.12.1 and earlier Patched on: 1.12.2 Our engineering team is currently assessing our entire hosting fleet and determining next steps. If you have any further questions or concerns, please contact us at [email protected] or via Live Chat.

  2. identified Sep 26, 2026, 04:10 PM UTC

    We have identified that only a subset of hosts are reported with the vulnerable Site Import extension. Our team is mitigating this vulnerability by upgrading this extension to the patched version. Meanwhile, your time and patience will be appreciated.

  3. resolved Sep 27, 2026, 02:50 AM UTC

    Our team has completed the remediation work for the affected environments. No further action is required at this time. Thank you for your patience.