Investigating - A security vulnerability, CVE-2026-65640, has been identified in WordPress that could allow an authenticated Author-level or higher user to achieve remote code execution through a malicious file upload on sites using Imagick and Ghostscript.
The vulnerability has been addressed through updates across supported WordPress branches.
Patched Versions:
Customers should update to the following patched version for their respective WordPress branch: 7.0.4 6.9.7 6.8.8 6.7.7 6.6.7 6.5.10 6.4.10 6.3.10 6.2.11 6.1.12 6.0.14 5.9.16 5.8.15 5.7.17 5.6.19 5.5.20 5.4.21 5.3.23 5.2.26 5.1.24 5.0.27 4.9.31 4.8.30 4.7.35
Recommended Action:
Customers are strongly encouraged to update WordPress core to the latest available patched version and ensure automatic updates are enabled where appropriate.
Customers with automatic updates enabled should receive the applicable update automatically. However, we recommend verifying the currently running WordPress version to ensure the security update has been successfully applied.
We will continue to monitor the situation and provide further updates if required.
If you need assistance or have any concerns, please reach us via live chat or via a case.
Investigating - A high-severity reflected XSS vulnerability, CVE-2026-64638, has been identified in the WordPress login interface. Exploitation requires a victim to visit a specially crafted URL and, under specific conditions, could potentially lead to PHP code execution.
Impacted versions: WordPress 4.7 – 7.0.2 (every release on every branch) WordPress 4.6 and earlier — end of life, no patch available
Fixed versions: WordPress 7.0.3 WordPress 6.9.6 WordPress 6.8.7 Equivalent minor releases on every remaining supported branch back to 4.7
Recommended Action Customers are strongly encouraged to update WordPress core and ensure automatic security updates are enabled where appropriate. Since exploitation requires user interaction, customers should also remain vigilant against phishing attempts and avoid clicking suspicious or unsolicited links. Customers with automatic security updates enabled should receive the applicable update automatically; however, we recommend verifying the currently running WordPress version. There is currently no reported evidence of widespread exploitation in the wild. We will continue to monitor the situation and provide further updates if required.
If you need assistance or have any concerns, please contact our Support team.
Aug 08, 2026 - 09:28 EDT
Support Services
Operational
Tickets
Operational
Phones
Operational
Chats
Operational
Help Center
Operational
Platform Operations
Operational
Web Services
Operational
DNS
Operational
SSH/FTP
Operational
Email
Operational
MySQL
Operational
InterWorx Control Panel
Operational
Cluster / NFS
Operational
Platform Updates / Other
Operational
Managed Wordpress
Operational
Wordpress Core Updates
Operational
Wordpress Plugin Updates via Visual Compare
Operational
Nexcess Cloud
Operational
us-midwest-1
Operational
us-west-1
Operational
uk-south-2
Operational
nl-west-1
Operational
au-south-1
Operational
us-midwest-2
Operational
Cloud Container Services
Operational
us-midwest-1
Operational
us-west-1
Operational
uk-south-2
Operational
nl-west-1
Operational
au-south-1
Operational
us-midwest-2
Operational
Nexcess Global DNS
Operational
Customer Portal
Operational
Safe Harbor Updates
Operational
Data Centers & Network
Operational
90 days ago
100.0
% uptime
Today
Southfield, MI (MEL)
Operational
90 days ago
100.0
% uptime
Today
Dearborn, MI (OTR)
Operational
90 days ago
100.0
% uptime
Today
San Jose, CA (SJC)
Operational
90 days ago
100.0
% uptime
Today
Miami, FL (MIA)
Operational
90 days ago
100.0
% uptime
Today
Surrey, UK (LHR)
Operational
90 days ago
100.0
% uptime
Today
West Sussex, UK (LGW)
Operational
90 days ago
100.0
% uptime
Today
Amsterdam, NL (AMS)
Operational
90 days ago
100.0
% uptime
Today
Sydney, AU (SYD)
Operational
90 days ago
100.0
% uptime
Today
Lansing, MI (DC3)
Operational
90 days ago
100.0
% uptime
Today
Operational
Degraded Performance
Partial Outage
Major Outage
Maintenance
Major outage
Partial outage
No downtime recorded on this day.
No data exists for this day.
had a major outage.
had a partial outage.
Related
No incidents or maintenance related to this downtime.
Past Incidents
Aug 13, 2026
No incidents reported today.
Aug 12, 2026
Unresolved incident: Security Advisory: WordPress Security Update for CVE-2026-65640.
Resolved -
The issue affecting a subset of our servers in the us-west-1 region has been resolved. Our team has restored service, and the affected servers are operating normally.
We apologize for any disruption this may have caused and appreciate your patience and understanding while we worked to resolve the issue.
Aug 11, 04:30 EDT
Monitoring -
Our team has now implemented a fix, and affected servers and services should be operating as expected at this time. We will continue to monitor the situation closely to ensure ongoing stability.
If you have any questions or concerns, please contact us via live chat or case.
Aug 11, 02:39 EDT
Investigating -
We are currently investigating an issue affecting a subset of our servers in the us-west-1 region. Our systems engineers have been engaged and are working to restore service as quickly as possible. We appreciate your patience.
If you have any questions or concerns. Please contact us via live chat or case.
Aug 11, 01:55 EDT
Resolved -
This incident has been resolved.
Aug 8, 07:48 EDT
Monitoring -
Our Engineers have successfully restored service to the affected servers, and all services are currently operating normally.
The incident is now in a monitoring state. We will continue to watch the environment closely to ensure stability following the restoration of service.
We appreciate your patience throughout this incident and will provide additional updates if there are any significant changes.
If you have any questions or concerns, please feel free to reach out to our support team via Live Chat or by opening a Support Case.
Aug 7, 21:25 EDT
Investigating -
Our Engineers are investigating an interruption in service affecting cloudhost-2915341.us-midwest-1.nxcli.net & cloudhost-2915335.us-midwest-1.nxcli.net. We understand the inconvenience this may cause and truly appreciate your patience while we resolve the issue.
If you have any questions or concerns, please feel free to reach out to our support team via Live Chat or by opening a Support Case.
Aug 7, 19:32 EDT
Resolved -
The security updates have been applied across our fleet.
Aug 6, 09:07 EDT
Identified -
Our teams are continuing to deploy the required security updates across affected systems in response to the Januscape Vulnerability (CVE-2026-53359). As part of this remediation, some systems require a controlled reboot to complete the patching process.
Following each reboot, we are validating system availability, service health, and network connectivity. Systems that do not return to service as expected are being actively investigated and restored by our operations teams.
We understand the importance of maintaining availability and are working carefully to complete this remediation while minimizing customer impact. Additional updates will be provided as patching and validation efforts continue.
Jul 13, 13:51 EDT
Investigating -
Our team is currently assessing the impact and scope of Januscape Vulnerability (CVE-2026-53359), and its impact on servers in our fleet and the best way to apply patches to our hosting infrastructure.
We will be sending communications to any affected customers as we work to apply the necessary mitigations.
Next Steps: Teams are currently in review of vulnerability; subsequent status updates will follow.
Jul 9, 10:36 EDT
Resolved -
This incident has been resolved.
Aug 4, 07:51 EDT
Monitoring -
Our engineers have successfully recovered the service on the impacted cloudhost.
We are continuing to monitor the environment to ensure stability and will keep this space updated as needed.
Aug 4, 05:24 EDT
Identified -
The issue has been identified, and our teams are actively working toward a resolution.
We will provide further updates as more information becomes available. Thank you for your patience.
Aug 4, 04:40 EDT
Investigating -
We are currently investigating a service-impacting issue affecting the server cloudhost-1189763.au-south-1.nxcli.net. Our Nexcess Systems Engineering team has been engaged and is actively working to restore service as quickly as possible.
We appreciate your patience and understanding while we work to resolve this issue. If you have any questions or concerns, please don't hesitate to contact us via live chat or by opening a support case.
Aug 4, 01:31 EDT