<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Plesk Migrator - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/plesk-migrator/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 27 Aug 2026 15:11:15 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/plesk-migrator/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Security Vulnerabilities in Plesk Management Interface and Extensions</title><link>https://feed.craftedsignal.io/briefs/2026-08-webpros-advisory/</link><pubDate>Thu, 27 Aug 2026 15:11:15 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-webpros-advisory/</guid><description>WebPros has released security updates for Plesk and its Migrator and Site Import extensions to address critical vulnerabilities CVE-2026-65642 and CVE-2026-65647.</description><content:encoded><![CDATA[<p>WebPros has issued a security advisory (AV26-854) identifying vulnerabilities impacting its flagship Plesk hosting management platform and several associated extensions. The flaws include CVE-2026-65642, which affects the Plesk database management interface, and CVE-2026-65647, which affects the Plesk Site Import and Plesk Migrator extensions. These vulnerabilities present risks to server security and database administration workflows. WebPros has released patched versions for Plesk (versions 18.0.79.8, 18.0.80.4, and later), Plesk Migrator (version 2.36.0 and later), and Plesk Site Import (version 1.12.1 and later). Administrators are encouraged to prioritize these updates to mitigate the risk of unauthorized database access or exploit attempts targeting the affected management extensions.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of these vulnerabilities could result in unauthorized access, data exposure, or administrative disruption within the Plesk environment. Given that Plesk is widely utilized by hosting providers and site administrators to manage complex server configurations, these vulnerabilities could enable attackers to gain control over hosted databases or leverage administrative extension functions to impact multiple sites on a shared server.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Apply the security patches for Plesk by upgrading to version 18.0.79.8 or 18.0.80.4 immediately.</li>
<li>Update the Plesk Migrator extension to at least version 2.36.0.</li>
<li>Update the Plesk Site Import extension to at least version 1.12.1.</li>
<li>Audit administrative access logs for unusual activity targeting the Plesk database management interface or extension execution logs following the update.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>vulnerability</category><category>patch-management</category><category>web-hosting</category></item></channel></rss>