Investigating - A security vulnerability, CVE-2026-65640, has been identified in WordPress that could allow an authenticated Author-level or higher user to achieve remote code execution through a malicious file upload on sites using Imagick and Ghostscript.
The vulnerability has been addressed through updates across supported WordPress branches.
Patched Versions:
Customers should update to the following patched version for their respective WordPress branch: 7.0.4 6.9.7 6.8.8 6.7.7 6.6.7 6.5.10 6.4.10 6.3.10 6.2.11 6.1.12 6.0.14 5.9.16 5.8.15 5.7.17 5.6.19 5.5.20 5.4.21 5.3.23 5.2.26 5.1.24 5.0.27 4.9.31 4.8.30 4.7.35
Recommended Action:
Customers are strongly encouraged to update WordPress core to the latest available patched version and ensure automatic updates are enabled where appropriate.
Customers with automatic updates enabled should receive the applicable update automatically. However, we recommend verifying the currently running WordPress version to ensure the security update has been successfully applied.
We will continue to monitor the situation and provide further updates if required.
If you need assistance or have any concerns, please reach us via live chat or via a case.
Investigating - A high-severity reflected XSS vulnerability, CVE-2026-64638, has been identified in the WordPress login interface. Exploitation requires a victim to visit a specially crafted URL and, under specific conditions, could potentially lead to PHP code execution.
Impacted versions
Impacted versions: WordPress 4.7 – 7.0.2 (every release on every branch) WordPress 4.6 and earlier — end of life, no patch available
Fixed versions: WordPress 7.0.3 WordPress 6.9.6 WordPress 6.8.7 Equivalent minor releases on every remaining supported branch back to 4.7
Recommended Action Customers are strongly encouraged to update WordPress core and ensure automatic security updates are enabled where appropriate. Since exploitation requires user interaction, customers should also remain vigilant against phishing attempts and avoid clicking suspicious or unsolicited links. Customers with automatic security updates enabled should receive the applicable update automatically; however, we recommend verifying the currently running WordPress version. There is currently no reported evidence of widespread exploitation in the wild. We will continue to monitor the situation and provide further updates if required.
If you need assistance or have any concerns, please contact our Support team.
Aug 08, 2026 - 09:24 EDT
We will be performing routine updates to Acronis agents to prepare for upcoming system upgrades. This maintenance is part of our standard update schedule.
These updates will be applied automatically, and no action is required from you. We do not anticipate any service disruption or downtime during this process. There is a small chance that this update could temporarily interrupt backups. Our team will actively monitor the deployment to ensure continued stability.
If you have any questions or require assistance, please reach out to our support team and we will be happy to assist
We will be performing scheduled maintenance on our network infrastructure on September 3, 2026, at 04:00 UTC. The maintenance is expected to last approximately 1 hour.
This work is being performed to improve network redundancy and long-term stability.
For the vast majority of customers, no impact to public traffic or external Internet connectivity is expected.
Customers with infrastructure spanning our Lansing (DC2/DC3) and London (DC12) data centers may experience a brief 10–20 second period of increased latency for traffic routed specifically between these locations during the maintenance.
Our engineering team will closely monitor the network throughout the maintenance to ensure the work is completed safely and with minimal disruption.
We appreciate your patience while we make these improvements to our network infrastructure.
If you have any questions or require assistance, please reach out to our support team and we will be happy to assist.
Completed -
The scheduled maintenance has been completed.
Aug 27, 09:00 EDT
In progress -
Scheduled maintenance is currently in progress. We will provide updates as necessary.
Aug 26, 09:00 EDT
Scheduled -
Liquid Web Systems Engineers will be performing maintenance on our Object Storage platform starting at 9:00 AM on Wednesday and will be performing routine maintenance during the next 24 hours. While this upgrade is expected to have no impact in the functionality of Object Storage, it is possible, though unexpected, that data transfers may progress more slowly or briefly stall, before automatically resuming Object Storage.
We appreciate your patience as our Engineering team works to enhance the performance of our platform. If you have any further questions or concerns please reach out to our support teams [CC-13721]
Aug 21, 13:11 EDT
Completed -
The scheduled maintenance has been completed.
Aug 25, 22:00 EDT
In progress -
Scheduled maintenance is currently in progress. We will provide updates as necessary.
Aug 25, 21:00 EDT
Scheduled -
Liquid Web Network Engineers will be performing scheduled maintenance to add additional capacity to our DC3 data center. No service impact is expected though some customers may experience brief latency while network loads converge.
Our support team is on hand should you need any assistance or have any questions or concerns. You can reach us through the following channels: