CVE-2026-68487: WebPros Plesk
Critical severity, CVSS 9.9. EPSS: 0.6% chance of exploitation in the next 30 days.
Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.
Affected products
- WebPros Plesk: up to and including 18.0.80.6; up to and including 18.0.79.10
Published 2026-09-10. Last modified 2026-09-10.