Back to Security Advisories
High 2026-07-22

Security Advisory: Plesk PHP Updater Remote Code Execution

Plesk AlmaLinux 9 CloudLinux 9 Debian 12 Ubuntu 22.04

A vulnerability in the Plesk PHP Updater allows an authenticated admin to write files outside the intended directory, leading to remote code execution as the psaserv service user.

Affected Versions

Plesk Obsidian 18.0.63 and earlier

Patched Version

Plesk Obsidian 18.0.65

Default Update CMD

yum update -y

Fix Commands

AlmaLinux 9 / CloudLinux 9

plesk installer update --select-product-id plesk
plesk sbin packagemng --update

Ubuntu 22.04 / Debian 12

apt update
plesk installer update --select-product-id plesk
More Information

Check your system for vulnerabilities

Select your product and operating system to see the exact fix commands that apply to you.

Check Your System