CVE-2026-64636: WebPros Plesk
High severity, CVSS 7.7. EPSS: 0.4% chance of exploitation in the next 30 days.
An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and Windows allows an authenticated user to read arbitrary data from the panel database.
Affected products
- WebPros Plesk: from 18.0.51, before 18.0.80.1 (fixed in 18.0.80.1)
Published 2026-08-07. Last modified 2026-09-03.