Investigating - A high-severity reflected XSS vulnerability, CVE-2026-64638, has been identified in the WordPress login interface. Exploitation requires a victim to visit a specially crafted URL and, under specific conditions, could potentially lead to PHP code execution.
Impacted versions
Impacted versions: WordPress 4.7 – 7.0.2 (every release on every branch) WordPress 4.6 and earlier — end of life, no patch available
Fixed versions: WordPress 7.0.3 WordPress 6.9.6 WordPress 6.8.7 Equivalent minor releases on every remaining supported branch back to 4.7
Recommended Action Customers are strongly encouraged to update WordPress core and ensure automatic security updates are enabled where appropriate. Since exploitation requires user interaction, customers should also remain vigilant against phishing attempts and avoid clicking suspicious or unsolicited links. Customers with automatic security updates enabled should receive the applicable update automatically; however, we recommend verifying the currently running WordPress version. There is currently no reported evidence of widespread exploitation in the wild. We will continue to monitor the situation and provide further updates if required.
If you need assistance or have any concerns, please contact our Support team.
Aug 08, 2026 - 09:24 EDT
We are performing critical network infrastructure upgrades to significantly improve network stability and reliability. This work involves upgrading the DWDM (Dense Wavelength Division Multiplexing) system capacity from 200G to 400G between our data centers and the ATT network.
This maintenance is scheduled to begin Wednesday, August 12, at 9:30 am ET, and is expected to last for 3 hours.
While we typically strive to perform network maintenance outside of business hours, this one will take place inside business hours, due to the specific availability requirements of our third-party vendors.
To maintain operational continuity during this process, multiple layers of redundancy are in place to support these upgrades. While we do not anticipate any service outages, some users may experience brief latency in rare situations as traffic routes adjust. We appreciate your understanding as we complete these necessary performance enhancements. Posted on
Aug 07, 2026 - 12:37 EDT
Completed -
The scheduled maintenance has been completed.
Aug 3, 07:00 EDT
In progress -
Scheduled maintenance is currently in progress. We will provide updates as necessary.
Aug 3, 04:00 EDT
Scheduled -
We will be performing planned maintenance on our core network infrastructure, affecting DC2 (Lansing), DC3 (Lansing), Ashburn POP, and Chicago POP network locations.
Maintenance Window: [Aug 03, 2026, 4:00 AM ET] (Up to 3 hours)
No service outage is expected. Customers may experience brief latency fluctuations (approximately ±20 ms) while network traffic is optimized across redundant paths.
Our engineering team will monitor the maintenance closely throughout the change window.
Jul 31, 13:25 EDT
Resolved -
Service has been restored at this time, and the affected VMware MT-hosted services are operating normally.
Thank you for your patience and understanding while our teams worked to resolve this issue.
Jul 31, 22:07 EDT
Investigating -
We are investigating intermittent connectivity and increased latency affecting some services hosted in the VMware MT environment.
Our engineers are actively working to identify the cause and restore normal service as quickly as possible.
We appreciate your patience and understanding while we work to resolve this issue. If you have any questions or concerns, please open a support ticket or contact us via chat.
Jul 31, 21:34 EDT
Resolved -
The security updates have been applied across the Liquid Web fleet.
Jul 29, 15:28 EDT
Identified -
Our teams are continuing to deploy the required security updates across affected systems in response to the Januscape Vulnerability (CVE-2026-53359). As part of this remediation, some systems require a controlled reboot to complete the patching process.
Following each reboot, we are validating system availability, service health, and network connectivity. Systems that do not return to service as expected are being actively investigated and restored by our operations teams.
We understand the importance of maintaining availability and are working carefully to complete this remediation while minimizing customer impact. Additional updates will be provided as patching and validation efforts continue.
Jul 13, 13:49 EDT
Investigating -
Our team is currently assessing the impact and scope of Januscape Vulnerability (CVE-2026-53359), and its impact on servers in our fleet and the best way to apply patches to our hosting infrastructure.
We will be sending communications to any affected customers as we work to apply the necessary mitigations.
Next Steps: Teams are currently in review of vulnerability; subsequent status updates will follow.
Jul 9, 10:34 EDT
Completed -
The scheduled maintenance has been completed.
Jul 27, 12:00 EDT
In progress -
Scheduled maintenance is currently in progress. We will provide updates as necessary.
Jul 27, 04:00 EDT
Scheduled -
Liquid Web Network Engineers are performing scheduled maintenance on the network infrastructure connecting our Lansing, MI and Chicago, IL facilities. This work is part of our ongoing investment in network capacity and reliability, and will strengthen the performance of this route going forward.
Maintenance window: July 27, 2026, 4:00 AM – 12:00 PM ET (up to 8 hours)
There is no expected service interruption during this window. As traffic is temporarily rerouted while we complete the upgrade, some customers may notice a slight, temporary change in latency (round-trip time) — in either direction. This is a normal, expected part of the process and does not indicate a problem with your service.
No action is needed on your end. If you notice anything unexpected during or after this window, Our support team is on standby to help or if you have questions or concerns.
You can connect with us through the following channels: