Nexcess incident

Januscape Vulnerability (CVE-2026-53359)

Minor Resolved View vendor source →

Nexcess experienced a minor incident on July 9, 2026 affecting us-midwest-1 and us-west-1 and 1 more component, lasting 27d 22h. The incident has been resolved; the full update timeline is below.

Started
Jul 09, 2026, 02:36 PM UTC
Resolved
Aug 06, 2026, 01:07 PM UTC
Duration
27d 22h
Detected by Pingoru
Jul 09, 2026, 02:36 PM UTC

Affected components

us-midwest-1us-west-1uk-south-2nl-west-1au-south-1us-midwest-2

Update timeline

  1. investigating Jul 09, 2026, 02:36 PM UTC

    Our team is currently assessing the impact and scope of Januscape Vulnerability (CVE-2026-53359), and its impact on servers in our fleet and the best way to apply patches to our hosting infrastructure. We will be sending communications to any affected customers as we work to apply the necessary mitigations. Next Steps: Teams are currently in review of vulnerability; subsequent status updates will follow.

  2. identified Jul 13, 2026, 05:51 PM UTC

    Our teams are continuing to deploy the required security updates across affected systems in response to the Januscape Vulnerability (CVE-2026-53359). As part of this remediation, some systems require a controlled reboot to complete the patching process. Following each reboot, we are validating system availability, service health, and network connectivity. Systems that do not return to service as expected are being actively investigated and restored by our operations teams. We understand the importance of maintaining availability and are working carefully to complete this remediation while minimizing customer impact. Additional updates will be provided as patching and validation efforts continue.

  3. resolved Aug 06, 2026, 01:07 PM UTC

    The security updates have been applied across our fleet.