CVE-2025-66430: Plesk

Critical severity, CVSS 9.1. EPSS: 0.6% chance of exploitation in the next 30 days.

Plesk 18.0 has Incorrect Access Control.

Affected products

  • Plesk Plesk: from 18.0.70, before 18.0.73.5 (fixed in 18.0.73.5); from 18.0.74, before 18.0.74.2 (fixed in 18.0.74.2)

Published 2025-12-12. Last modified 2026-06-17.