Nexcess Server Incident History
Nexcess Server is currently operational with all systems functioning normally.
Incident History
Showing incidents from the last 15 days
Report: "WP2Shell Wordpress Core Critical Remote Code Execution Vulnerabilities, CVE-2026-60137 and CVE-2026-63030"
Last updateThe Nexcess Managed Wordpress platform configures Wordpress Core updates by default and the vast majority of websites have been updated. Nexcess System Engineers proactively attempted to update affected websites that were not already on the patched version. In some cases this was not possible to do. The Nexcess Managed Wordpress Development team has pushed a must-use plugin that mitigates this vulnerability where the application is not on a patched version. All customers are strongly encouraged to ensure their websites have been updated to the latest version of Wordpress.
Our teams continue to work diligently to assess the impact of the recently disclosed WordPress Core vulnerabilities and verify that appropriate mitigation measures are in place. We remain actively engaged in our investigation and are monitoring the situation for any new developments. We will continue to closely monitor the situation and take any additional steps necessary to maintain system security and stability. If you need assistance or have any concerns, please contact our Support team.
On July 17th Wordpress.org announced two critical remote code execution (RCE) vulnerabilities commonly known as WP2Shell. These vulnerabilities exist in Wordpress Core and allow an unauthenticated request to execute arbitrary code on the target website. Customers running the Wordpress versions below are strongly advised to upgrade to latest version shown as soon as possible: Wordpress 6.8.x; fixed in 6.8.6 WordPress 6.9.x; fixed in 6.9.5 WordPress 7.0.x; fixed in 7.0.2 WordPress 7.1 beta, fixed in 7.1 beta2 Source: https://wordpress.org/news/2026/07/wordpress-7-0-2-release/
Report: "Januscape Vulnerability (CVE-2026-53359)"
Last updateOur teams are continuing to deploy the required security updates across affected systems in response to the Januscape Vulnerability (CVE-2026-53359). As part of this remediation, some systems require a controlled reboot to complete the patching process. Following each reboot, we are validating system availability, service health, and network connectivity. Systems that do not return to service as expected are being actively investigated and restored by our operations teams. We understand the importance of maintaining availability and are working carefully to complete this remediation while minimizing customer impact. Additional updates will be provided as patching and validation efforts continue.
Our team is currently assessing the impact and scope of Januscape Vulnerability (CVE-2026-53359), and its impact on servers in our fleet and the best way to apply patches to our hosting infrastructure. We will be sending communications to any affected customers as we work to apply the necessary mitigations. Next Steps: Teams are currently in review of vulnerability; subsequent status updates will follow.
Report: "Service Interruption on Cloudhost | 76771"
Last updateThis incident has been resolved.
Our Engineering team has resolved the issue, and the host is now back online. We are continuing to monitor the environment to ensure stability and will keep this space updated as needed.
We have encountered an issue with a CloudHost, and our engineers have identified the cause. The team is actively working towards a resolution. We understand the impact this may have and will continue to provide updates here as progress is made. In the meantime, if you have any questions, please do not hesitate to contact our Support team via chat or email.
Report: "Service Interruption on Cloudhost | 76771"
Last updateThis incident has been resolved.
Our Engineering team has resolved the issue, and the host is now back online.We are continuing to monitor the environment to ensure stability and will keep this space updated as needed.
We have encountered an issue with a CloudHost, and our engineers have identified the cause. The team is actively working towards a resolution.We understand the impact this may have and will continue to provide updates here as progress is made. In the meantime, if you have any questions, please do not hesitate to contact our Support team via chat or email.
Report: "Security Advisory: Update Avada Builder and UpdraftPlus WordPress Plugins Immediately"
Last updateThis advisory is now being closed. We encourage our customers to ensure that any affected WordPress plugins have been updated to the latest available versions and continue following WordPress security best practices. If you believe your website may have been impacted or require assistance, please contact our Support team.
We are advising all customers using WordPress to verify that the following plugins are updated to the latest available versions. Recently disclosed vulnerabilities affect older versions of these plugins: CVE-2026-6279 – Avada Builder (Fusion Builder) – Unauthenticated Remote Code Execution Affected versions: 3.15.2 and earlier CVE-2026-10795 – UpdraftPlus Backup Plugin – Authentication Bypass Affected versions: 1.26.4 and earlier These vulnerabilities may allow unauthenticated attackers to gain control of vulnerable WordPress sites and compromise WordPress user accounts if the plugins have not been updated to the latest available versions. If your website uses either of these plugins, we strongly recommend that you: Update the affected plugin(s) to the latest available version immediately. Review your WordPress installation for any unexpected administrator accounts, plugins, or modified files. Contact our Support team if you believe your website has been affected or if you need assistance reviewing your installation.
Report: "Januscape Vulnerability (CVE-2026-53359)"
Last updateOur team is currently assessing the impact and scope of Januscape Vulnerability (CVE-2026-53359), and its impact on servers in our fleet and the best way to apply patches to our hosting infrastructure. We will be sending communications to any affected customers as we work to apply the necessary mitigations.Next Steps:Teams are currently in review of vulnerability; subsequent status updates will follow.
Report: "Security Advisory: Update Avada Builder and UpdraftPlus WordPress Plugins Immediately"
Last updateThis advisory is now being closed. We encourage our customers to ensure that any affected WordPress plugins have been updated to the latest available versions and continue following WordPress security best practices. If you believe your website may have been impacted or require assistance, please contact our Support team.
We are advising all customers using WordPress to verify that the following plugins are updated to the latest available versions.Recently disclosed vulnerabilities affect older versions of these plugins:CVE-2026-6279 – Avada Builder (Fusion Builder) – Unauthenticated Remote Code ExecutionAffected versions: 3.15.2 and earlierCVE-2026-10795 – UpdraftPlus Backup Plugin – Authentication BypassAffected versions: 1.26.4 and earlierThese vulnerabilities may allow unauthenticated attackers to gain control of vulnerable WordPress sites and compromise WordPress user accounts if the plugins have not been updated to the latest available versions.If your website uses either of these plugins, we strongly recommend that you:Update the affected plugin(s) to the latest available version immediately.Review your WordPress installation for any unexpected administrator accounts, plugins, or modified files.Contact our Support team if you believe your website has been affected or if you need assistance reviewing your installation.
Report: "Scheduled SSH service Maintenance on EL9 Cloudhosts"
Last updateThe scheduled maintenance has been completed.
Scheduled maintenance is currently in progress. We will provide updates as necessary.
Our Engineering team will be performing scheduled maintenance on SSH service configuration on every Enterprise Linux9 cloudhosts. This maintenance is being performed to enhance ssh service security and ensure continued protection against evolving security risks.This change is isolated strictly to the SSH service and legacy cryptographic algorithms will remain temporarily enabled during this phase, ensuring that older SSH clients can still connect.- Maintenance Window: July 8, 2026 at 04:00AM ET- Duration: 2 to 3 hoursOur team will be actively monitoring the process throughout the maintenance and will keep informing you about any other changes made.Our support team is on standby if you need help, have questions, or have concerns. You can connect with us through the following channels:Live Chat: https://portal.liquidweb.com/Email: support@liquidweb.comWe appreciate your patience and understanding as we perform this maintenance to improve our infrastructure and continue providing reliable service.Thank you for your continued support.Internal System Maintenance Reference: [CC-13578]