CVE-2026-87898
OS command injection in Plesk allows remote authenticated users to execute arbitrary code with root privileges.
- Published Sep 23, 2026
- CVSS 9.4 critical
- 1.0% chance of exploitation in the next 30 days (EPSS)
Affected software
In the news
- WebPros security advisory (AV26-961) Canadian Centre for Cyber Security ยท