CVE-2026-68489EPSS p50.4%
CVE-2026-68489CVE-2026-68489
Description
Static Code Injection in Plesk extensions "Ruby" before 1.6.6 and "Node.js Toolkit" before 2.5.0 allows remote authenticated users to execute arbitrary code as root via custom environment variables.
Scoring
| EPSS | 0.67% probability of exploitation · percentile 50.4% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-18 |