Question
Is the Plesk affected by CVE-2026-23918?
Answer
The issue affects Apache 2.4.66 and its http2 module specifically.
Plesk uses Apache from OS repositories, so if the OS distribution provides Apache 2.4.66 - it is affected by the issue.
If Apache 2.4.66 is installed - update Apache to the version 2.4.67 (manually via CLI, or via Tools & Settings > System Updates menu).
Apache version can be checked OS package manager, or via Tools & Settings > Server Components menu.
- Connect to the server via SSH
-
Check currently installed Apache version:
- On Ubuntu/Debian:
# apt info apache2
Package: apache2
Version: 2.4.52-1ubuntu4.19
Priority: optional
Section: web
Origin: Ubuntu
Maintainer: Ubuntu Developers ubuntu-devel-discuss@lists.ubuntu.com
Original-Maintainer: Debian Apache Maintainers debian-apache@lists.debian.org
...- On RHEL-like (RHEL, CentOS, AlmaLinux, Rocky Linux, CloudLinux):
# yum info httpd
Installed Packages
Name : httpd
Version : 2.4.62
Release : 7.el9_7.3
Architecture : x86_64
Size : 59 k
Source : httpd-2.4.62-7.el9_7.3.src.rpm
Repository : @System
... -
Check for available updates and :
- On Ubuntu/Debian:
# apt update && apt list --upgradable
Note: On Ubuntu/Debian updates are intsalled with
apt upgradecommand- On RHEL-like (RHEL, CentOS, AlmaLinux, Rocky Linux, CloudLinux):
# yum update
- Log into Plesk
- Navigate to Tools & Settings > Apache & Nginx Settings
- Disable the following modules:
http2,proxy_http2 - Connect to the server via SSH
- Check the status of Nginx:
# plesk sbin nginxmng --status
If the command provides Disabled, then Apache-only setup is used.
- Verify if the
example.com(some hosted domain or Plesk hostname) uses HTTP/2 or HTTP/1.1:
# curl -IvLk https://example.com
Output like below should be provided when HTTP/1.1 is used:
* Trying 203.0.113.2:80...
* Connected to example.com (203.0.113.2) port 80 (#0)
> HEAD / HTTP/1.1
> Host: example.com
> User-Agent: curl/7.81.0
> Accept: */*
>
* Mark bundle as not supporting multiuse
< HTTP/1.1 301 Moved Permanently
HTTP/1.1 301 Moved Permanently
< Date: Wed, 06 May 2026 11:23:49 GMT
Date: Wed, 06 May 2026 11:23:49 GMT
< Server: Apache
Server: Apache
< Location: https://example.com/
Location: https://example.com/
< Content-Type: text/html; charset=iso-8859-1
Content-Type: text/html; charset=iso-8859-1
<
* Connection #0 to host example.com left intact
Comments
Apache 2.4.66 users on Plesk should take note—this CVE directly impacts the HTTP/2 module. Since Plesk relies on the OS-provided Apache packages, affected servers will need to upgrade to 2.4.67 right away. Check your current version through the Server Components panel or your package manager, then apply the update either manually via CLI or through the System Updates interface in Plesk. Don't delay on this one if you're running 2.4.66.
Security updates like this are a good reminder to keep track of system changes while also staying on top of longer term planning. For people navigating employment based immigration, having a clear view of processing stages and expected wait times can make planning easier. You can read more about the green card timeline and use it as a general planning reference.
Please sign in to leave a comment.