Liquid Web incident

Security Advisory: WordPress Security Update for CVE-2026-65640

Notice Resolved View vendor source →

Liquid Web experienced a notice incident on August 12, 2026, lasting 21d 22h. The incident has been resolved; the full update timeline is below.

Started
Aug 12, 2026, 03:44 PM UTC
Resolved
Sep 03, 2026, 01:52 PM UTC
Duration
21d 22h
Detected by Pingoru
Aug 12, 2026, 03:44 PM UTC

Update timeline

  1. investigating Aug 12, 2026, 03:44 PM UTC

    A security vulnerability, CVE-2026-65640, has been identified in WordPress that could allow an authenticated Author-level or higher user to achieve remote code execution through a malicious file upload on sites using Imagick and Ghostscript. The vulnerability has been addressed through updates across supported WordPress branches. Patched Versions: Customers should update to the following patched version for their respective WordPress branch: 7.0.4 6.9.7 6.8.8 6.7.7 6.6.7 6.5.10 6.4.10 6.3.10 6.2.11 6.1.12 6.0.14 5.9.16 5.8.15 5.7.17 5.6.19 5.5.20 5.4.21 5.3.23 5.2.26 5.1.24 5.0.27 4.9.31 4.8.30 4.7.35 Recommended Action: Customers are strongly encouraged to update WordPress core to the latest available patched version and ensure automatic updates are enabled where appropriate. Customers with automatic updates enabled should receive the applicable update automatically. However, we recommend verifying the currently running WordPress version to ensure the security update has been successfully applied. We will continue to monitor the situation and provide further updates if required. If you need assistance or have any concerns, please reach us via live chat or via a case. Additional information: https://wordpress.org/news/2026/08/wordpress-7-0-4-release/ https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-8vr3-7mxf-gx8w

  2. resolved Sep 03, 2026, 01:52 PM UTC

    The WordPress security vulnerability CVE-2026-65640 has been addressed in the latest WordPress security releases. Customers are encouraged to keep their WordPress installations updated to the latest available security release within their current supported branch. We have proactively contacted customers identified as running potentially affected WordPress versions and provided recommendations to update their installations. At this time, the incident has been resolved, and the related status page notification will be closed.