Investigating - A security vulnerability, CVE-2026-65640, has been identified in WordPress that could allow an authenticated Author-level or higher user to achieve remote code execution through a malicious file upload on sites using Imagick and Ghostscript.

The vulnerability has been addressed through updates across supported WordPress branches.

Patched Versions:

Customers should update to the following patched version for their respective WordPress branch:
7.0.4
6.9.7
6.8.8
6.7.7
6.6.7
6.5.10
6.4.10
6.3.10
6.2.11
6.1.12
6.0.14
5.9.16
5.8.15
5.7.17
5.6.19
5.5.20
5.4.21
5.3.23
5.2.26
5.1.24
5.0.27
4.9.31
4.8.30
4.7.35


Recommended Action:

Customers are strongly encouraged to update WordPress core to the latest available patched version and ensure automatic updates are enabled where appropriate.

Customers with automatic updates enabled should receive the applicable update automatically. However, we recommend verifying the currently running WordPress version to ensure the security update has been successfully applied.

We will continue to monitor the situation and provide further updates if required.

If you need assistance or have any concerns, please reach us via live chat or via a case.

Additional information:
https://wordpress.org/news/2026/08/wordpress-7-0-4-release/
https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-8vr3-7mxf-gx8w

Aug 12, 2026 - 11:45 EDT
Investigating - A high-severity reflected XSS vulnerability, CVE-2026-64638, has been identified in the WordPress login interface. Exploitation requires a victim to visit a specially crafted URL and, under specific conditions, could potentially lead to PHP code execution.

Impacted versions:
WordPress 4.7 – 7.0.2 (every release on every branch)
WordPress 4.6 and earlier — end of life, no patch available

Fixed versions:
WordPress 7.0.3
WordPress 6.9.6
WordPress 6.8.7
Equivalent minor releases on every remaining supported branch back to 4.7


Recommended Action
Customers are strongly encouraged to update WordPress core and ensure automatic security updates are enabled where appropriate. Since exploitation requires user interaction, customers should also remain vigilant against phishing attempts and avoid clicking suspicious or unsolicited links.
Customers with automatic security updates enabled should receive the applicable update automatically; however, we recommend verifying the currently running WordPress version.
There is currently no reported evidence of widespread exploitation in the wild. We will continue to monitor the situation and provide further updates if required.

If you need assistance or have any concerns, please contact our Support team.

Aug 08, 2026 - 09:28 EDT
Support Services Operational
Tickets Operational
Phones Operational
Chats Operational
Help Center Operational
Platform Operations Operational
Web Services Operational
DNS Operational
SSH/FTP Operational
Email Operational
MySQL Operational
InterWorx Control Panel Operational
Cluster / NFS Operational
Platform Updates / Other Operational
Managed Wordpress Operational
Wordpress Core Updates Operational
Wordpress Plugin Updates via Visual Compare Operational
Nexcess Cloud Operational
us-midwest-1 Operational
us-west-1 Operational
uk-south-2 Operational
nl-west-1 Operational
au-south-1 Operational
us-midwest-2 Operational
Cloud Container Services Operational
us-midwest-1 Operational
us-west-1 Operational
uk-south-2 Operational
nl-west-1 Operational
au-south-1 Operational
us-midwest-2 Operational
Nexcess Global DNS Operational
Customer Portal Operational
Safe Harbor Updates Operational
Data Centers & Network Operational
90 days ago
100.0 % uptime
Today
Southfield, MI (MEL) Operational
90 days ago
100.0 % uptime
Today
Dearborn, MI (OTR) Operational
90 days ago
100.0 % uptime
Today
San Jose, CA (SJC) Operational
90 days ago
100.0 % uptime
Today
Miami, FL (MIA) Operational
90 days ago
100.0 % uptime
Today
Surrey, UK (LHR) Operational
90 days ago
100.0 % uptime
Today
West Sussex, UK (LGW) Operational
90 days ago
100.0 % uptime
Today
Amsterdam, NL (AMS) Operational
90 days ago
100.0 % uptime
Today
Sydney, AU (SYD) Operational
90 days ago
100.0 % uptime
Today
Lansing, MI (DC3) Operational
90 days ago
100.0 % uptime
Today
Operational
Degraded Performance
Partial Outage
Major Outage
Maintenance
Major outage
Partial outage
No downtime recorded on this day.
No data exists for this day.
had a major outage.
had a partial outage.

Scheduled Maintenance

Nexcess EADN Origin Shield Maintenance Aug 26, 2026 22:00-23:00 EDT

Nexcess System Engineers will be performing scheduled maintenance on Edge Application Delivery Network (EADN) Origin Shields that provide the Nexcess CDN Service available in the Managed Wordpress, Managed Woo Commerce, and Managed Magento customer portals. EADN Web services will be reloaded during the window which may cause a brief (< 1min) packet loss, latency, or reconnection for websites using the built-in CDN service.

Our support team is on hand should you need any assistance or have any questions or concerns. You can reach us through the following channels:

Live Chat: https://my.nexcess.net/
Email: support@nexcess.net

We appreciate your patience and understanding as we complete this maintenance.

Internal System Maintenance Reference: CC-13718

Posted on Aug 24, 2026 - 16:04 EDT

Aug 26, 2026

No incidents reported today.

Aug 25, 2026

No incidents reported.

Aug 24, 2026

Resolved - We have completed our review of this issue and are closing this incident.

The root cause was identified as a compatibility issue within the WP Rocket plugin following the WordPress 7.1 update. WP Rocket has released a fix, and customers can resolve the issue by updating the plugin to version 3.23.2.2 or later.

As this involves a third-party plugin, we are not performing automated plugin updates across customer environments. However, we conducted a fleet-wide review to identify customers using affected WP Rocket versions and proactively communicated the issue, available fix, and recommended actions to those customers.

Customers who continue to experience issues can contact our Support team for assistance with disabling the plugin or for guidance on updating WP Rocket to a fixed version.

No further actions are pending from our side, and this incident is now considered closed.

Aug 24, 10:03 EDT
Investigating - We are aware of an issue affecting some WordPress websites using the WP Rocket plugin following the WordPress 7.1 update. This may result in website interruptions or fatal errors.

Resolution: WP Rocket has released a fix in version 3.23.2.2.

If your website is affected, please update the WP Rocket plugin to version 3.23.2.2 or later. If you are unable to update the plugin, WP Rocket has also provided temporary workarounds in their documentation:

https://docs.wp-rocket.me/article/1927-fatal-error-on-wordpress-7-1

We will provide additional updates as more information becomes available.

If you have any questions or concerns, please don't hesitate to contact us via live chat or by opening a support case.

Aug 20, 07:28 EDT

Aug 23, 2026

No incidents reported.

Aug 22, 2026

No incidents reported.

Aug 21, 2026

Completed - The scheduled maintenance has been completed.
Aug 21, 06:00 EDT
In progress - Scheduled maintenance is currently in progress. We will provide updates as necessary.
Aug 20, 22:00 EDT
Scheduled - To support our ongoing commitment to platform security and performance, we are performing scheduled maintenance to upgrade the Interworx control panel. This work is necessary to assist with moving off of end of life software versions.

During this window our engineering team will perform upgrades to Interworx. Customer websites will remain operational and unaffected by this maintenance. Access to the Interworx Portal will be temporarily restricted until the upgrade completes.

We apologize for any inconvenience this may cause and appreciate your patience as we make these necessary improvements to our infrastructure.

Aug 14, 13:31 EDT

Aug 20, 2026

Completed - The scheduled maintenance has been completed.
Aug 20, 06:00 EDT
In progress - Scheduled maintenance is currently in progress. We will provide updates as necessary.
Aug 19, 22:00 EDT
Scheduled - To support our ongoing commitment to platform security and performance, we are performing scheduled maintenance to upgrade the Interworx control panel. This work is necessary to assist with moving off of end of life software versions.

During this window our engineering team will perform upgrades to Interworx. Customer websites will remain operational and unaffected by this maintenance. Access to the Interworx Portal will be temporarily restricted until the upgrade completes.

We apologize for any inconvenience this may cause and appreciate your patience as we make these necessary improvements to our infrastructure.

Aug 14, 13:30 EDT

Aug 19, 2026

Completed - The scheduled maintenance has been completed.
Aug 19, 06:00 EDT
In progress - Scheduled maintenance is currently in progress. We will provide updates as necessary.
Aug 18, 22:00 EDT
Scheduled - To support our ongoing commitment to platform security and performance, we are performing scheduled maintenance to upgrade the Interworx control panel. This work is necessary to assist with moving off of end of life software versions.

During this window our engineering team will perform upgrades to Interworx. Customer websites will remain operational and unaffected by this maintenance. Access to the Interworx Portal will be temporarily restricted until the upgrade completes.

We apologize for any inconvenience this may cause and appreciate your patience as we make these necessary improvements to our infrastructure.

Aug 14, 13:28 EDT

Aug 18, 2026

Resolved - This incident has been resolved.
Aug 18, 16:16 EDT
Investigating - This issue is currently affecting the ability to create new Magento, Wordpress, and WooCommerce websites and some dedicated cloud plans through the Nexcess customer portal. Nexcess Engineering and Development teams are currently reviewing the service impact and evaluating options to return service as quickly as possible. We will provide further updates as soon as they are available.

We appreciate your patience as our team works to resolve this issue. If you have further questions or concerns, please contact us at support@nexcess.net or via Live Chat.

Aug 17, 12:27 EDT
Identified - GitHub is reporting degraded performance via their status page this morning:
https://www.githubstatus.com/

Per the page, this problem may be affecting Pull Requests, Issues, Copilot, Actions, Webhooks, and API requests, among other services. Customers should follow the GitHub status page for the latest information.

Aug 17, 11:35 EDT
Resolved - This incident has been resolved.
Aug 18, 15:30 EDT
Monitoring - Service has been successfully restored on the impacted cloudhost.

We are continuing to monitor the environment to ensure stability and will keep this space updated as needed.

Aug 16, 22:02 EDT
Identified - The issue has been identified, and our teams are actively working toward a resolution.

We will provide further updates as more information becomes available. Thank you for your patience.

Aug 16, 19:32 EDT
Investigating - We are currently investigating a service-impacting issue affecting the server cloudhost-4895770.us-midwest-2.nxcli.net. Our Nexcess Systems Engineering team has been engaged and is actively working to restore service as quickly as possible.

We appreciate your patience and understanding while we work to resolve this issue. If you have any questions or concerns, please don't hesitate to contact us via live chat or by opening a support case.

Aug 16, 17:34 EDT
Completed - The scheduled maintenance has been completed.
Aug 18, 11:00 EDT
In progress - Scheduled maintenance is currently in progress. We will provide updates as necessary.
Aug 18, 08:30 EDT
Scheduled - We are performing scheduled maintenance on our cooling infrastructure to optimize system efficiency and performance. Services are expected to remain fully operational during this maintenance window. Thank you for your patience as we make these improvements.
Aug 14, 12:33 EDT

Aug 17, 2026

Aug 16, 2026

Aug 15, 2026

No incidents reported.

Aug 14, 2026

No incidents reported.

Aug 13, 2026

No incidents reported.

Aug 12, 2026

Unresolved incident: Security Advisory: WordPress Security Update for CVE-2026-65640.