Pantheon Status · History · Incident #143695
RESOLVEDSecurity Advisory: Malicious Activity Affecting Platform Hosts
Minor · Started Oct 1, 2026 · 12:38 PM
Pantheon Status · History · Incident #143695
RESOLVEDMinor · Started Oct 1, 2026 · 12:38 PM
Duration
5d 2h 43m
Severity
Minor
Detection lead
—
User reports
—
Summary
This incident has been resolved.
Started
Oct 1, 2026 · 12:38 PM
Resolved
Oct 6, 2026 · 3:21 PM
Duration
5d 2h 43m
Severity
None
Event timeline
Monitoring
Oct 1 · 12:38 PM PantheonBeginning September 29, Pantheon identified malicious activity in which an attacker gained control of a customer website and used it to target platform resources. Activity from the compromised site attempted to exploit a Linux kernel vulnerability (CVE-2026-53362) on platform application hosts, and some sites may have briefly experienced interruptions as a result. We have taken the following actions: - Disabled and deleted the affected site. - Accelerated the operating-system and kernel updates already in progress, bringing application hosts to a version that addresses this vulnerability. - Deployed additional platform protections and monitoring. We have notified the affected customer directly. The compromise was limited to that single site; based on the information available to us, we have found no evidence of platform-wide data exfiltration or that this activity exposed data belonging to other customers. We are continuing to review platform activity and will update this advisory if that changes. How to protect your site: Attackers most often gain control of a site through outdated or unmaintained code. Keeping your site current is the most effective protection. We strongly encourage all customers to keep CMS core, plugins, and themes fully updated, remove and delete sites and code you no longer use, and review user and credential access. If you notice unexpected code, deployments, or changes on your site, contact Pantheon Support. We will post updates here as more information becomes available. If you have questions, please contact Pantheon Support.
Monitoring
Oct 2 · 8:05 AM PantheonAs our investigation has continued, we have determined that a small number of customer sites — not one — were affected. In each case, the site was first compromised through a weakness in its own application, then used to interact with platform services. We are working directly with the affected customers on cleanup and credential rotation, and we have added platform controls to restrict this activity and detection to identify it going forward. The activity remains limited to the individual affected sites and their own data. We have found no evidence that any other customer's site or data was accessed. What you can do: Keeping your site current is the most effective protection. Please update your CMS core, plugins, themes, and modules to the latest versions; remove plugins, themes, and modules you don't use; and delete sites you no longer need. If you notice unexpected code, deployments, or changes on your site, contact Pantheon Support. We will continue to post updates here.
Monitoring
Oct 3 · 9:29 AM PantheonWe are continuing to monitor and work through the remaining remediation and hardening. Our initial response is complete, and we are now working directly with the affected customers on site cleanup and credential rotation. We have added further protections and monitoring to help prevent and detect this type of activity. Based on the information available to us, we have found no evidence that any other customer's site or data was accessed. We will share another update as the remaining work progresses. As a reminder, the most effective protection is keeping your site current: please keep your CMS, plugins, themes, and modules up to date, remove anything you no longer use, review your user and credential access, and contact Pantheon Support if you notice unexpected code, deployments, or other changes on your site.
Monitoring
Oct 5 · 11:08 AM PantheonRemediation and platform hardening remain ongoing. We are continuing to monitor systems closely while working directly with affected customers.
Resolved
Oct 6 · 3:21 PM PantheonThis incident has been resolved.
Pattern
Add it as a dependency monitor. The Free plan includes one.
Stay online, all the time, with Pulsetic's uptime prime.
By Designmodo
Designmodo Inc. 169 Madison Ave, #79627, New York, NY 10016, United States
Copyright © 2010-2026. Pulsetic® is a registered trademark.