Live / Incidents / Nexcess
Nexcess: Security Advisory: WordPress Security Update for CVE-2026-65640
Nexcess · nexcess.netImpact: noneResolved2026-08-12 15:45 UTC
Public — what happened
Summary
A security vulnerability, CVE-2026-65640, has been identified in WordPress that could allow an authenticated Author-level or higher user to achieve remote code execution through a malicious file upload on sites using Imagick and Ghostscript.
The vulnerability has been addressed through updates across supported WordPress branches.
Patched Versions:
Customers should update to the following patched version for their respective WordPress branch:
7.0.4
6.9.7
6.8.8
6.7.7
6.6.7
6.5.10
6.4.10
6.3.10
6.2.11
6.1.12
6.0.14
5.9.16
5.8.15
5.7.17
5.6.19
5.5.20
5.4.21
5.3.23
5.2.26
5.1.24
5.0.27
4.9.31
4.8.30
4.7.35
Recommended Action:
Customers are strongly encouraged to update WordPress core to the
Timeline
- Started — 2026-08-12 15:45 UTC
- Last update — 2026-08-12 15:45 UTC
- Resolved — 2026-09-02 20:36 UTC
With SquidGrid — where it starts on the route
Independent path health
The status page is the symptom. SquidGrid measures the paths that reach Nexcess against their own baselines — whether the routes carrying your traffic degraded, at which handoff, and who owns that stretch.
🔒 Sign in to seeCustomers get the live Provider Assessment Report for Nexcess: its full incident track record, what tends to break, and recent public reports of problems.
Included with any paid plan.
Open the Nexcess report →