WebPros disclosed CVE-2026-64636, a blind SQL injection vulnerability in Plesk Obsidian affecting both Linux and Windows deployments. The flaw impacts Plesk for Linux versions 18.0.51 through 18.0.80 and Plesk for Windows 18.0.80 and earlier; WebPros said successful exploitation could let an attacker extract data from the server database through a read-only SQL injection. The issue is tracked in WebPros security advisory AV26-790 and was responsibly disclosed by Aziz Knani.
WebPros released fixes in Plesk Obsidian versions 18.0.80.1 and 18.0.79.5 and urged administrators to apply the latest hotfix build immediately. As temporary mitigations, the company advised restricting reseller system logins and reseller API access until patching is complete. The advisory was also circulated through the Canadian Centre for Cyber Security, underscoring the need for prompt remediation across exposed hosting environments.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
A WebPros security advisory identified as AV26-790 was dated for CVE-2026-64636, confirming that Plesk Obsidian versions prior to 18.0.80.1 and 18.0.79.5 are affected by the blind SQL injection vulnerability. The notice referenced the advisory via the Canadian Centre for Cyber Security.
Plesk published guidance for CVE-2026-64636, stating that Linux versions 18.0.51 through 18.0.80 and Windows 18.0.80 and earlier are affected, and that fixes are available in versions 18.0.80.1 and 18.0.79.5. It also urged administrators to update immediately and provided temporary mitigations such as disabling reseller system logins and reseller API access.
Plesk said CVE-2026-64636, a blind SQL injection vulnerability affecting Plesk for Linux and Windows, was responsibly disclosed by Aziz Knani. The flaw could allow read-only extraction of data from the server database.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.