CVE-2026-65647: WebPros Plesk Migrator
High severity, CVSS 8.7. EPSS: 0.7% chance of exploitation in the next 30 days.
Improper symlink resolution before file access in Plesk allows remote authenticated users to execute arbitrary code as root.
Affected products
- WebPros Plesk Migrator: before 2.36.0 (fixed in 2.36.0)
- WebPros Plesk Site Import: before 1.12.1 (fixed in 1.12.1)
Published 2026-08-26. Last modified 2026-09-03.