CVE-2026-68488: WebPros Plesk
Critical severity, CVSS 9.9. EPSS: 0.4% chance of exploitation in the next 30 days.
A Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk causes local privilege escalation to root via arbitrary file/directory ownership takeover.
Affected products
- WebPros Plesk: up to and including 18.0.80.6; up to and including 18.0.79.10
Published 2026-09-10. Last modified 2026-09-10.