{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/plesk-migrator/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"id":"CVE-2026-65642"},{"id":"CVE-2026-65647"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Plesk","Plesk Migrator","Plesk Site Import"],"_cs_severities":["medium"],"_cs_tags":["vulnerability","patch-management","web-hosting"],"_cs_type":"advisory","_cs_vendors":["WebPros"],"content_html":"\u003cp\u003eWebPros has issued a security advisory (AV26-854) identifying vulnerabilities impacting its flagship Plesk hosting management platform and several associated extensions. The flaws include CVE-2026-65642, which affects the Plesk database management interface, and CVE-2026-65647, which affects the Plesk Site Import and Plesk Migrator extensions. These vulnerabilities present risks to server security and database administration workflows. WebPros has released patched versions for Plesk (versions 18.0.79.8, 18.0.80.4, and later), Plesk Migrator (version 2.36.0 and later), and Plesk Site Import (version 1.12.1 and later). Administrators are encouraged to prioritize these updates to mitigate the risk of unauthorized database access or exploit attempts targeting the affected management extensions.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities could result in unauthorized access, data exposure, or administrative disruption within the Plesk environment. Given that Plesk is widely utilized by hosting providers and site administrators to manage complex server configurations, these vulnerabilities could enable attackers to gain control over hosted databases or leverage administrative extension functions to impact multiple sites on a shared server.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eApply the security patches for Plesk by upgrading to version 18.0.79.8 or 18.0.80.4 immediately.\u003c/li\u003e\n\u003cli\u003eUpdate the Plesk Migrator extension to at least version 2.36.0.\u003c/li\u003e\n\u003cli\u003eUpdate the Plesk Site Import extension to at least version 1.12.1.\u003c/li\u003e\n\u003cli\u003eAudit administrative access logs for unusual activity targeting the Plesk database management interface or extension execution logs following the update.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-27T15:11:15Z","date_published":"2026-08-27T15:11:15Z","id":"https://feed.craftedsignal.io/briefs/2026-08-webpros-advisory/","summary":"WebPros has released security updates for Plesk and its Migrator and Site Import extensions to address critical vulnerabilities CVE-2026-65642 and CVE-2026-65647.","title":"Security Vulnerabilities in Plesk Management Interface and Extensions","url":"https://feed.craftedsignal.io/briefs/2026-08-webpros-advisory/"}],"language":"en","title":"CraftedSignal Threat Feed - Plesk Migrator","version":"https://jsonfeed.org/version/1.1"}