Live / Incidents / Nexcess
Nexcess: Security Advisory: Critical WordPress Vulnerability - "Click2Shell"
Nexcess · nexcess.netImpact: noneResolved2026-09-25 19:19 UTC
Public — what happened
Summary
As part of our proactive security efforts, Nexcess System Engineers scanned our fleet and automatically upgraded WordPress installations where possible to the appropriate patched versions. Automated update attempts were unsuccessful for some websites due to site-specific errors. Customers with websites that were unable to be upgraded should receive a ticket identifying the server and path to the website.
All customers are strongly encouraged to confirm the Wordpress version for all of the websites, including those in staging or development, have been updated to the latest minor version of Wordpress released on September 22nd in order to protect the website from this exploit.
For additio
Timeline
- Started — 2026-09-22 20:13 UTC
- Last update — 2026-09-25 19:19 UTC
- Resolved — 2026-09-25 19:19 UTC
With SquidGrid — where it starts on the route
Independent path health
The status page is the symptom. SquidGrid measures the paths that reach Nexcess against their own baselines — whether the routes carrying your traffic degraded, at which handoff, and who owns that stretch.
🔒 Sign in to seeCustomers get the live Provider Assessment Report for Nexcess: its full incident track record, what tends to break, and recent public reports of problems.
Included with any paid plan.
Open the Nexcess report →