CVE-2026-65646EPSS p51.4%

CVE-2026-65646CVE-2026-65646

Description

Improper neutralization of special elements in in Plesk's DNS zone management functionality allows remote authenticated users to disclose arbitrary local files and escalate privileges.

Scoring

CVSS 9.9 ()
VectorCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS0.70% probability of exploitation · percentile 51.4% · 2026-10-05T12:00:23Z
Last modified2026-09-11
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.