CVE-2026-68487: WebPros Plesk

Critical severity, CVSS 9.9. EPSS: 0.6% chance of exploitation in the next 30 days.

Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.

Affected products

  • WebPros Plesk: up to and including 18.0.80.6; up to and including 18.0.79.10

Published 2026-09-10. Last modified 2026-09-10.