Plesk disclosed and patched CVE-2026-44962, a critical privilege-escalation flaw in Plesk on Linux that allows a low-privileged authenticated user to execute arbitrary operating system commands on affected servers. The bug stems from an XPath injection issue in the APS Application Catalog search function, where unsanitized input is inserted into XPath queries, enabling remote exploitation without user interaction. The vulnerability carries a CVSS 10.0 rating and can lead to administrative access and full compromise of server resources, with particular risk for shared hosting and other multi-tenant deployments.
Plesk released fixes in versions 18.0.76.2 and 18.0.75.1, and advised administrators to update immediately. For systems that cannot yet be patched, the company said the APS subsystem should be disabled through the panel.ini configuration file and management components restarted. The flaw was responsibly disclosed by Georgii Shutiaev, and reports said there was no public evidence of active exploitation at the time of publication, though defenders were urged to review access controls and monitor for suspicious command execution.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
Plesk released patches for the critical privilege-escalation and command-execution flaw CVE-2026-44962 in late February 2026. The fixes were made available in versions 18.0.76.2 and 18.0.75.1, and Plesk also provided a temporary mitigation to disable the APS subsystem or catalog.
The critical Plesk on Linux vulnerability CVE-2026-44962 was publicly disclosed as an XPath injection flaw in the APS Application Catalog search functionality. The disclosure stated that an authenticated low-privileged user could execute arbitrary OS commands and potentially gain administrative access, and noted the issue was responsibly disclosed by Georgii Shutiaev.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
4 references tracked. Mallory keeps watching after this page renders.
cyber.gc.ca
Open sourcecybersecuritynews.com
Open sourcesecurityonline.info
Open sourcesupport.plesk.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.