Investigating - WebPros (cPanel) posted news regarding a critical privilege-escalation vulnerability within the LiteSpeed software. A malicious website user could potentially gain root-level access to the server (even bypassing account isolation controls such as CageFS).

More Information can be found here:
https://support.cpanel.net/hc/en-us/articles/43483286674583-Security-LiteSpeed-Enterprise-security-advisory-September-14-2026

We will attempt to update LiteSpeed to the patched version (6.3.7) where we are able to via Automation. Regardless, please ensure your Litespeed is up-to-date.

If you have any questions or concerns, please contact support@liquidweb.com

Sep 14, 2026 - 16:32 EDT
Update - Our technical teams continue to actively work through the remediation process across affected environments.
The patch rollout is progressing in batches, with teams continuing to apply the available Adobe security patch across affected Magento versions.

We are also continuing system scans and validation of patched environments to help ensure affected sites can be safely restored to a known-good state.
We will continue to keep clients informed as meaningful progress is made.

If you need assistance or have any concerns, please contact our Support team.

Sep 10, 2026 - 04:15 EDT
Update - Our Engineering teams continue to make progress on containment, investigation, and remediation across affected environments.

Adobe has recently released a patch addressing the underlying vulnerability. Our technical teams are actively applying the patch across affected environments in batches. There is no specific priority or ordering for the affected Magento versions; the rollout is progressing batch by batch, with our teams continuing to apply the patch across all affected versions.

At the same time, we will continue deep-system scans and validate the patched environments to ensure safe recovery paths and restore impacted sites to a known-good state.

We will continue to share updates as additional remediation details and progress become available.

If you need assistance or have any concerns, please contact our Support team.

Sep 09, 2026 - 18:52 EDT
Update - Our technical teams continue to make progress on containment, investigation, and remediation across affected environments.

Adobe has recently released a patch addressing the underlying vulnerability.
Our technical teams are actively reviewing, testing, and deploying the patch while continuing deep-system scans and validating safe recovery paths to restore impacted sites to a known-good state.

We will continue to share updates as new remediation details become available.
Please contact Support if you have any questions or require assistance in the meantime.

Sep 08, 2026 - 02:24 EDT
Update - Our Security and Engineering teams remain actively engaged in the ongoing containment, investigation, and remediation efforts across affected environments.

Our teams continue to review scanning results, validate findings, and take appropriate remediation actions where potential compromise has been identified. Restoration efforts are also progressing as we work to safely return affected sites to a known-good state.

We understand the importance and urgency of this situation and appreciate your continued patience. We will provide further updates as meaningful progress is made and additional remediation details become available.

If you need assistance or have any concerns, please contact our Support team.

Sep 07, 2026 - 11:06 EDT
Update - Our Security and Engineering teams continue to work on containment and remediation efforts across affected environments. Deep-system scanning remains active as we work to identify, isolate, and quarantine compromised instances.

Restoration planning is also ongoing, with our technical teams validating safe recovery paths for impacted sites. While a precise time-to-resolution is still being established, restoring full system integrity safely remains our highest priority.

We appreciate your continued patience as this work continues. We will provide another status update as soon as there are meaningful developments or milestones to share.

If you need assistance or have any concerns, please contact our Support team.

Sep 07, 2026 - 02:21 EDT
Update - Our Security and Engineering teams remain actively engaged and are continuing to investigate the affected environments. Confirmed threats are being quarantined as part of our ongoing containment efforts, while findings are reviewed and validated.

We are also preparing to begin restoration work where necessary. An estimated restoration timeline is not yet available, but we will share additional details as soon as they are confirmed. This remains a high priority, and we will continue to provide updates as progress is made.

Sep 06, 2026 - 17:53 EDT
Update - Our teams remain actively engaged and are continuing to investigate the Magento vulnerability and its potential impact. Security and Engineering are working closely to validate findings, expand scanning, and provide clear remediation guidance for any confirmed cases.

We understand the importance and urgency of this situation and really appreciate your patience. This remains a high priority for us, and we’re here to support you throughout the process.

We recommend continuing to monitor your environment for unusual activity or unexpected changes. If you notice anything suspicious or believe your site may have been affected, please reach out to Support.

We’ll continue to closely monitor the situation and share further updates as more information becomes available. Thank you for your patience.

Sep 06, 2026 - 10:29 EDT
Update - Our security teams are actively scanning affected environments for indicators of compromise. Initial scanning has identified potential findings that are currently being reviewed and validated. We are continuing to enhance our scanning capabilities to provide additional visibility into potential compromises.

We are also reviewing affected Magento environments and developing remediation guidance for confirmed cases.

Customers may experience some impact if their storefront or applications rely heavily on GraphQL, including headless/PWA implementations.

We recommend continuing to monitor your environment for unusual activity or unexpected changes and contacting Support if you observe any issues or suspect your site may have been compromised.

Our teams will continue to monitor the situation closely and provide further updates as additional information becomes available.

Sep 06, 2026 - 05:08 EDT
Update - As part of our ongoing mitigation efforts, we have implemented additional security protections across affected Magento/Adobe Commerce environments. This includes a full block on GraphQL requests to help reduce the risk of unauthorized code execution.

Customers using headless/PWA storefronts or applications that rely heavily on GraphQL may experience some impact from these protections.

At this time, there is no official vendor patch available.

We recommend continuing to monitor your site for unusual activity or unexpected changes and contacting Support if you notice any issues with your storefront or suspect your site may have been compromised. We will provide further updates once an official security patch becomes available.

Our teams are continuing to monitor the affected environments and the effectiveness of these mitigations. We will continue to assess the situation and provide additional updates as new information becomes available.

Sep 05, 2026 - 19:04 EDT
Identified - We are aware of recent reports regarding a critical, unpatched zero-day vulnerability, commonly referred to as “StyleSmuggler”, affecting Magento and Adobe Commerce.

At this time, our teams are actively reviewing server environments to assess any potential impact. As a precautionary measure, our Security team is implementing the appropriate mitigations while we continue our investigation and monitor for further guidance.
We will provide further updates as more information becomes available.

If you need assistance or have any concerns, please contact our Support team .

Sep 05, 2026 - 09:51 EDT
API (example) Operational
Management Portal (example) Operational
API Operational
DNS Operational
Cloud Dedicated Operational
Cloud VPS Hosting Operational
CPanel Operational
InterWorx Operational
Plesk Operational
Object Storage Operational
VMware Cloud Operational
VMware Private Cloud Operational
Business Email Operational
Management Portal Operational
Load Balancers Operational
Cloud Load Balancers Operational
Shared Load Balancers - DC2 Operational
Shared Load Balancers - DC3 Operational
Shared Load Balancers - DC4 Operational
Shared Load Balancers - DC5 Operational
Network Operational
LAN Network Operational
PHX Network Operational
AMS Network Operational
Data Centers Operational
DC2 - LAN Operational
DC3 - LAN Operational
DC4 - PHX Operational
EU - AMS Operational
Support Services Operational
Chat Operational
Case Operational
Phone Operational
Operational
Degraded Performance
Partial Outage
Major Outage
Maintenance
Major outage
Partial outage
No downtime recorded on this day.
No data exists for this day.
had a major outage.
had a partial outage.

Scheduled Maintenance

Liquidweb Portal Maintenance Sep 15, 2026 08:00-09:00 EDT

We will be performing scheduled maintenance on the Liquidweb portal(https://portal.liquidweb.com/) on September 15, 2026, from 8:00 AM to 9:00 AM ET.

This maintenance includes updates to the portal’s checkout and payment experience, along with other improvements and updates.

The portal may experience brief interruptions during the maintenance window. No action is required.

If you have any questions or require assistance, please reach out to our support team and we will be happy to assist

Internal ref: CC-13767 & CC-13769

Posted on Sep 14, 2026 - 12:56 EDT

Scheduled Network maintenance at the DC5, Amsterdam Data Center Oct 6, 2026 11:00-16:00 EDT

Liquid Web Network Engineers will perform scheduled maintenance on the Core Network Devices and Border Network Devices supporting the Amsterdam Data Center. This work is part of our ongoing efforts to improve network connectivity, performance, reliability, and scalability.

Maintenance Window: October 6, 2026, at 11:00 AM ET
Expected Duration: Up to 5 hours

At this time, no service interruptions or increased latency are expected for customer services during the maintenance window.

Our Support team will be available throughout the maintenance period should you have any questions or require assistance. You can reach us through the following channels:

Live Chat: https://portal.liquidweb.com
Email: support@liquidweb.com

We appreciate your understanding and patience as we continue to enhance our infrastructure and services.

Thank you for your continued support.

Internal System Maintenance Reference: [CC-13765]

Posted on Sep 11, 2026 - 15:37 EDT

Scheduled Network maintenance at the DC5, Amsterdam Data Center Oct 7, 2026 11:00-16:00 EDT

Liquid Web Network Engineers will perform scheduled maintenance on the Core Network Devices and Border Network Devices supporting the Amsterdam Data Center. This work is part of our ongoing efforts to improve network connectivity, performance, reliability, and scalability.

Maintenance Window: October 7, 2026, at 11:00 AM ET
Expected Duration: Up to 5 hours

At this time, no service interruptions or increased latency are expected for customer services during the maintenance window.

Our Support team will be available throughout the maintenance period should you have any questions or require assistance. You can reach us through the following channels:

Live Chat: https://portal.liquidweb.com
Email: support@liquidweb.com

We appreciate your understanding and patience as we continue to enhance our infrastructure and services.

Thank you for your continued support.

Internal System Maintenance Reference: [CC-13765]

Posted on Sep 11, 2026 - 15:38 EDT

Sep 14, 2026

Unresolved incident: LiteSpeed security advisory.

Sep 13, 2026

No incidents reported.

Sep 12, 2026

Resolved - This incident has been resolved.
Sep 12, 09:55 EDT
Monitoring - Our engineers have successfully recovered the impacted cloud hosts.

We are continuing to monitor the environment to ensure stability and will keep this space updated as needed.

Sep 12, 04:35 EDT
Investigating - We are currently investigating a performance issue affecting a subset of our cloudhosts, cloudhost-4892688.us-midwest-2.nxcli.net and cloudhost-4892180.us-midwest-2.nxcli.net, in the US-Midwest-2 region. Customers may experience slowness or degraded performance, and there is a potential for service interruption while the issue is being investigated.

Our systems engineers have been engaged and are working to identify the cause and restore normal performance as quickly as possible.

We appreciate your patience. If you have any questions or concerns, please contact us via live chat or case.

Sep 12, 04:13 EDT

Sep 11, 2026

No incidents reported.

Sep 10, 2026

Completed - The scheduled maintenance has been completed.
Sep 10, 00:00 EDT
In progress - Scheduled maintenance is currently in progress. We will provide updates as necessary.
Sep 9, 22:00 EDT
Scheduled - Nexcess will be updating Composer from version 2.9.6 to 2.10.3 across the Nexcess platform. This update addresses the security vulnerability identified as CVE-2026-84361 and applies to customers who use Composer to manage their application dependencies.

Scheduled Date: September 9, 2026
Start Time: 10:00 PM EDT
Expected Duration: Approximately two hours

The update will be deployed gradually across the platform. No downtime or service interruption is anticipated, although some customers may experience brief periods of degraded performance while the update is applied.

No customer action is required. We will monitor the platform throughout the rollout to ensure services continue operating as expected. Our Support team will be available if you need assistance or have any questions or concerns.

You can contact us through the following channels:

Live Chat: https://portal.liquidweb.com
Email: support@liquidweb.com

Thank you,
The Nexcess Team

Sep 4, 14:05 EDT

Sep 9, 2026

Resolved - This incident has been resolved.
Sep 9, 17:26 EDT
Monitoring - Our engineers have successfully recovered the service on the impacted cloudhost.

We are continuing to monitor the environment to ensure stability and will keep this space updated as needed.

Sep 9, 07:54 EDT
Identified - The issue has been identified, and our teams are actively working toward a resolution.

We will provide further updates as more information becomes available. Thank you for your patience.

Sep 9, 07:50 EDT
Investigating - Our Engineers are investigating an interruption in service affecting cloudhost-9412708-us-midwest-1-nxcli-net and cloudhost-10309510.us-midwest-1.nxcli.net. We understand the inconvenience this may cause and truly appreciate your patience while we resolve the issue.

If you have any questions or concerns, please feel free to reach out to our support team via Live Chat or by opening a Support Case.

Sep 9, 07:27 EDT
Resolved - This incident has been resolved.
Sep 9, 17:24 EDT
Update - We have completed applying the security update across our hosting fleet to servers which we are able to access and patch but there still remains a subset of servers that we were unable to patch. This is partly due to End of Life software, e.g. cPanel on CentOS 6. Customers whose servers we were unable to patch should review their servers and ensure that their servers are running one of the following patched versions of cPanel:

v11.110.0.143
v11.134.0.55
v11.136.0.39
v11.138.0.4
WP2: v11.138.1.9

Any version of cPanel which is not running one of these versions is vulnerable and should be updated.

cPanel can be updated by using the following steps:
https://docs.cpanel.net/whm/cpanel/upgrade-to-latest-version/

For the customers on CentOS 6 (or older) we strongly suggest migrating to an Alma 9 server in order to receive future security patches

Sep 9, 17:23 EDT
Monitoring - The security patch for CVE-2026-67401 is being applied across the affected hosting fleet.

Our teams continue to monitor the environment and validate the patched systems. We have not observed any new issues since our last update.

We will provide further updates as needed. Thank you for your patience and understanding.

Sep 9, 02:00 EDT
Identified - We are currently applying the available security patches for CVE-2026-67401 across our hosting fleet.
Our teams are proactively triggering manual cPanel updates on affected servers in order to bring them to a patched version.
We are continuing to work through the affected fleet and will provide additional updates as remediation progresses.

Sep 8, 18:02 EDT
Investigating - We are currently evaluating the impact of the recently released CVE-2026-67401 — cPanel/WHM EmailTrack SQL Injection and its impact on our hosting fleet.

This vulnerability impacts all versions of cPanel.

It is patched in the following versions of cPanel
v11.110.0.143
v11.134.0.55
v11.136.0.39
v11.138.0.4
WP2: v11.138.1.9

Sep 8, 14:51 EDT

Sep 8, 2026

Sep 7, 2026

Sep 6, 2026

Sep 5, 2026

Sep 4, 2026

No incidents reported.

Sep 3, 2026

Resolved - This incident has been resolved.
Sep 3, 07:14 EDT
Identified - As an update regarding the ongoing latency issue:

Some customers may experience increased latency and/or intermittent service interruptions when traffic traverses affected network paths in the US West region. The issue has been linked to two separate fiber cuts impacting an upstream network provider in the Los Angeles and Honolulu areas.

The upstream provider's engineers are actively working to address both fiber cuts, and their third-party fiber vendor has also been engaged.

Our Network Administration team is continuing to monitor the situation closely. At this time, our monitoring indicates that customer sites remain operational, though some users may experience intermittent increased latency depending on their network path.

We will provide further updates as more information becomes available. We appreciate your patience and understanding.

Sep 2, 13:37 EDT
Investigating - We are currently investigating a performance issue affecting a subset of our servers in the au-south-1 region. Customers may experience slowness or degraded performance, and there is a potential for service interruption while the issue is being investigated.

Our systems engineers have been engaged and are working to identify the cause and restore normal performance as quickly as possible.

We appreciate your patience. If you have any questions or concerns, please contact us via live chat or case.

Sep 2, 11:05 EDT

Sep 2, 2026

Resolved - This incident has been resolved.
Sep 2, 23:33 EDT
Monitoring - The mitigation has taken effect, and the server is stable and operating normally. We have closely monitored the environment and have not observed any further issues.

If you experience any issues or need assistance, please reach out via Live Chat or by submitting a support case.

We appreciate your patience throughout this incident.

Sep 2, 21:27 EDT
Identified - Our teams have identified a distributed denial of service attack (DDOS) on cloudhost-2038507.us-west-1.nxcli.net. Our network engineers are already enabled for mitigation. We will provide another update as soon as more information becomes available.

If you have any questions or concerns, please contact us via live chat or case.

Sep 2, 20:08 EDT
Completed - The scheduled maintenance has been completed.
Sep 2, 17:00 EDT
In progress - Scheduled maintenance is currently in progress. We will provide updates as necessary.
Sep 2, 11:00 EDT
Scheduled - We will be performing routine updates to Acronis agents on our Managed Hosting Fleet to prepare for upcoming system upgrades. This maintenance is part of our standard update schedule.

These updates will be applied automatically, and no action is required from you. We do not anticipate any service disruption or downtime during this process. There is a small chance that this update could temporarily interrupt backups. Our team will actively monitor the deployment to ensure continued stability.

If you have any questions or require assistance, please reach out to our support team and we will be happy to assist

[REF CC-13737]

Aug 28, 14:04 EDT
Resolved - The WordPress security vulnerability CVE-2026-65640 has been addressed in the latest WordPress security releases.

Customers are encouraged to keep their WordPress installations updated to the latest available security release within their current supported branch.

We have proactively contacted customers identified as running potentially affected WordPress versions and provided recommendations to update their installations.

At this time, the incident has been resolved, and the related status page notification will be closed.

Sep 2, 16:35 EDT
Investigating - A security vulnerability, CVE-2026-65640, has been identified in WordPress that could allow an authenticated Author-level or higher user to achieve remote code execution through a malicious file upload on sites using Imagick and Ghostscript.

The vulnerability has been addressed through updates across supported WordPress branches.

Patched Versions:

Customers should update to the following patched version for their respective WordPress branch:
7.0.4
6.9.7
6.8.8
6.7.7
6.6.7
6.5.10
6.4.10
6.3.10
6.2.11
6.1.12
6.0.14
5.9.16
5.8.15
5.7.17
5.6.19
5.5.20
5.4.21
5.3.23
5.2.26
5.1.24
5.0.27
4.9.31
4.8.30
4.7.35


Recommended Action:

Customers are strongly encouraged to update WordPress core to the latest available patched version and ensure automatic updates are enabled where appropriate.

Customers with automatic updates enabled should receive the applicable update automatically. However, we recommend verifying the currently running WordPress version to ensure the security update has been successfully applied.

We will continue to monitor the situation and provide further updates if required.

If you need assistance or have any concerns, please reach us via live chat or via a case.

Additional information:
https://wordpress.org/news/2026/08/wordpress-7-0-4-release/
https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-8vr3-7mxf-gx8w

Aug 12, 11:46 EDT
Resolved - The WordPress security vulnerability CVE-2026-64638 has been addressed in the latest WordPress security releases.

Customers are encouraged to keep their WordPress installations updated to the latest available security release within their current supported branch.

We have proactively contacted customers identified as running potentially affected WordPress versions and provided recommendations to update their installations.

At this time, the incident has been resolved, and the related status page notification will be closed.

Sep 2, 16:33 EDT
Investigating - A high-severity reflected XSS vulnerability, CVE-2026-64638, has been identified in the WordPress login interface. Exploitation requires a victim to visit a specially crafted URL and, under specific conditions, could potentially lead to PHP code execution.

Impacted versions:
WordPress 4.7 – 7.0.2 (every release on every branch)
WordPress 4.6 and earlier — end of life, no patch available

Fixed versions:
WordPress 7.0.3
WordPress 6.9.6
WordPress 6.8.7
Equivalent minor releases on every remaining supported branch back to 4.7


Recommended Action
Customers are strongly encouraged to update WordPress core and ensure automatic security updates are enabled where appropriate. Since exploitation requires user interaction, customers should also remain vigilant against phishing attempts and avoid clicking suspicious or unsolicited links.
Customers with automatic security updates enabled should receive the applicable update automatically; however, we recommend verifying the currently running WordPress version.
There is currently no reported evidence of widespread exploitation in the wild. We will continue to monitor the situation and provide further updates if required.

If you need assistance or have any concerns, please contact our Support team.

Aug 8, 09:27 EDT

Sep 1, 2026

No incidents reported.

Aug 31, 2026

No incidents reported.