CVE-2026-68489
Static Code Injection in Plesk extensions "Ruby" before 1.6.6 and "Node.js Toolkit" before 2.5.0 allows remote authenticated users to execut
CVSS
—
No CVSS
EPSS
0.4%
p34
KEV
—
Exploit Today
10
0-100
Published: Sep 14, 2026 · Last modified: Sep 18, 2026 · CWE-96
0.4%EPSS · 30 days0.4%
2026-09-152026-09-22
Static Code Injection in Plesk extensions "Ruby" before 1.6.6 and "Node.js Toolkit" before 2.5.0 allows remote authenticated users to execute arbitrary code as root via custom environment variables.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-862189.8 CRI94.2%
KEV—78N-able N-central Static Code Injection Vulnerability14d