CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-58046

criticalCVSS 9.9covered by 2 sourcesfirst seen 2026-07-30
Serial number: AV26-761 Date: July 30, 2026 As of July 30, 2026, WebPros is affected by a vulnerability in the following product: Plesk Prior to 18.0.79.4 The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available. Vulnerability CVE-2026-58046: Blind SQL injection in Plesk's XML-RPC API – Plesk

CSIRTS triage

vendor: WebProsproduct: PleskSQL injectionaffected: Prior to 18.0.79.4
What
Blind SQL injection in Plesk's XML-RPC API.
Who is affected
Users and administrators of Plesk prior to version 18.0.79.4.
Urgency
Remediation is urgent due to the presence of a SQL injection vulnerability, which can be exploited.
Action
Users should update to Plesk version 18.0.79.4 or later.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-58046

Get an email if CVE-2026-58046 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-58046

CVE.org record

Embed the live status

CVE-2026-58046 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-58046 status](https://www.csirts.com/badge/CVE-2026-58046)](https://www.csirts.com/cve/CVE-2026-58046)