CVE-2026-65647: WebPros Plesk Migrator

High severity, CVSS 8.7. EPSS: 0.7% chance of exploitation in the next 30 days.

Improper symlink resolution before file access in Plesk allows remote authenticated users to execute arbitrary code as root.

Affected products

  • WebPros Plesk Migrator: before 2.36.0 (fixed in 2.36.0)
  • WebPros Plesk Site Import: before 1.12.1 (fixed in 1.12.1)

Published 2026-08-26. Last modified 2026-09-03.