Pantheon logo and current status indicator

Pantheon Incident History

Pantheon is currently operational with all systems functioning normally.

Last checked Jul 28, 2026 3:42 PM UTC from Pantheon's official status page

Incident History

Showing incidents from the last 15 days

Report: "Dashboard Login Issues"

Last update
resolved

This incident has been resolved. Google login option is now working as expected Thank you for your patience.

monitoring

A fix has been deployed, and the initial Dashboard login tests reflect positive results. Our team is closely monitoring. We will provide a final update once the resolution is verified. If you continue to experience the same issue, please contact us directly at helpdesk@pantheon.io.

investigating

We’re actively investigating the issue and will keep you updated. For urgent support, please contact helpdesk@pantheon.io.

investigating

We are currently experiencing an issue with the "Connect to Google" login option on the Pantheon Dashboard. All live sites remain fully operational and unaffected. Our engineering team is actively working to identify the root cause and implement a resolution. If you need immediate assistance, please contact us by email at helpdesk@pantheon.io. We will provide our next update as soon as more information becomes available.

Report: "Intermittent Dashboard Errors"

Last update
resolved

This incident has been resolved.

monitoring

A fix has been implemented and we are monitoring the results.

identified

The issue has been identified and a fix is being implemented. We'll provide further updates as soon as more information becomes available.

investigating

We are currently experiencing an issue causing intermittent errors within the Pantheon Dashboard. All live sites remain fully operational and unaffected. Our engineering team is actively working to identify the root cause and implement a resolution. If you require immediate assistance, please contact us via email: helpdesk@pantheon.io We will provide the next update as soon as more information becomes available.

Report: "Site availability issues"

Last update
resolved

This incident has been resolved.

monitoring

We are continuing to monitor the results. We will provide our next update in 3–4 hours, or sooner if new information becomes available. If you need immediate assistance or encounter any issues, please submit a support ticket at helpdesk@pantheon.io or contact us through live chat.

monitoring

The fix remains stable, with no new issues detected. We're continuing to monitor system metrics and logs to confirm the resolution holds. We'll post again once we have new findings.

monitoring

We are closely monitoring the recent fix and have not identified any new issues. We will provide further updates as they become available.

monitoring

We are continuing to monitor for any further issues.

monitoring

We've deployed a fix for the workflow availability issues and expect systems to recover shortly. Engineers are actively monitoring the rollout to confirm that pushing code, creating environments, and running scheduled tasks return to normal.

investigating

We're investigating site availability issues affecting workflows. This may impact your ability to push code, create environments, or run scheduled tasks. Our engineers are actively working on a fix, and we'll post updates here regularly.

Report: "WordPress 7.0.2 wp2shell"

Last update
resolved

This incident has been resolved.

monitoring

Network mitigations are now active and successfully blocking exploit attempts against vulnerable API endpoints without affecting normal site operations. Continuous monitoring is in place. This platform-level mitigation is a safeguard, not a permanent fix for your application. To fully secure your environment, update WordPress core immediately as detailed in the Pantheon Documentation: https://docs.pantheon.io/core-updates

monitoring

We are continuing to monitor traffic patterns and adapt network-level mitigations in response.

monitoring

We can observe our mitigations denying an increasing volume of requests and are continuing to gather data to enhance our response. We will provide an update Tuesday morning.

monitoring

Summary On July 17, 2026, the WordPress security team disclosed two chained vulnerabilities in WordPress core, publicly referred to as "wp2shell": - CVE-2026-60137 — a SQL injection issue in WordPress core (WP_Query / author__not_in). - CVE-2026-63030 — a REST API batch-route confusion issue which, chained with the above, can lead to unauthenticated remote code execution. Who is affected This affects specific versions of WordPress core: - 6.9.x — affected by both issues (RCE-capable). Patched in 6.9.6. - 7.0.x — affected by both issues (RCE-capable). Patched in 7.0.2. - 6.8.x — affected by the SQL injection issue only (not the full RCE chain). Patched in 6.8.6. Sites already on 6.8.6 / 6.9.6 / 7.0.2 or later, or on versions prior to 6.8, are not affected by this chain. Why it matters Chained together, these vulnerabilities can allow an unauthenticated attacker to execute code against a vulnerable site. Pantheon’s immutable containers prevent the deployment of webshells, bitcoin miners, or other exploits that leverage a downloaded payload in production environments. However, SQL Injection can still be used to deface or hijack sites. Because working exploits are publicly available, we expect attack volume to rise. What you should do — action required Update WordPress core to a patched version as soon as possible — 7.0.2, 6.9.6, or 6.8.6 depending on your branch — from your Pantheon Dashboard or via Terminus. Updating core is the definitive fix. See the WordPress 7.0.2 Security Release note: https://docs.pantheon.io/release-notes/2026/07/wordpress-7-0-2 What Pantheon is doing - We are actively monitoring platform traffic for exploitation attempts targeting the affected REST API endpoint. - We have observed sites being probed for vulnerability and have actively mitigated against sources of scripted activity already. - We are deploying targeted mitigations at the network level to programmatically prevent exploit attacks across the platform and can confirm that released exploit code is being mitigated. - Will update this post with more information as those efforts progress.