Our teams have identified a distributed denial of service attack (DDOS) on cloudhost-2038507.us-west-1.nxcli.net. Our network engineers are already enabled for mitigation. We will provide another update as soon as more information becomes available. If you have any questions or concerns, please contact us via live chat or case.
We are currently investigating a performance issue affecting a subset of our servers in the au-south-1 region. Customers may experience slowness or degraded performance, and there is a potential for service interruption while the issue is being investigated. Our systems engineers have been engaged and are working to identify the cause and restore normal performance as quickly as possible. We appreciate your patience. If you have any questions or concerns, please contact us via live chat or case.
We are investigating issues affecting the Nexcess Client Portal login at https://portal.nexcess.net/. Our engineering team is working to identify the cause and restore full availability as quickly as possible. We will provide updates as more information becomes available. We appreciate your patience and understanding during this time.
We are aware of an issue affecting some WordPress websites using the WP Rocket plugin following the WordPress 7.1 update. This may result in website interruptions or fatal errors. Resolution: WP Rocket has released a fix in version 3.23.2.2. If your website is affected, please update the WP Rocket plugin to version 3.23.2.2 or later. If you are unable to update the plugin, WP Rocket has also provided temporary workarounds in their documentation: https://docs.wp-rocket.me/article/1927-fatal-error-on-wordpress-7-1 We will provide additional updates as more information becomes available. If you have any questions or concerns, please don't hesitate to contact us via live chat or by opening a support case.
GitHub is reporting degraded performance via their status page this morning: https://www.githubstatus.com/ Per the page, this problem may be affecting Pull Requests, Issues, Copilot, Actions, Webhooks, and API requests, among other services. Customers should follow the GitHub status page for the latest information.
We are currently investigating a service-impacting issue affecting the server cloudhost-4895770.us-midwest-2.nxcli.net. Our Nexcess Systems Engineering team has been engaged and is actively working to restore service as quickly as possible. We appreciate your patience and understanding while we work to resolve this issue. If you have any questions or concerns, please don't hesitate to contact us via live chat or by opening a support case.
A security vulnerability, CVE-2026-65640, has been identified in WordPress that could allow an authenticated Author-level or higher user to achieve remote code execution through a malicious file upload on sites using Imagick and Ghostscript. The vulnerability has been addressed through updates across supported WordPress branches. Patched Versions: Customers should update to the following patched version for their respective WordPress branch: 7.0.4 6.9.7 6.8.8 6.7.7 6.6.7 6.5.10 6.4.10 6.3.10 6.2.11 6.1.12 6.0.14 5.9.16 5.8.15 5.7.17 5.6.19 5.5.20 5.4.21 5.3.23 5.2.26 5.1.24 5.0.27 4.9.31 4.8.30 4.7.35 Recommended Action: Customers are strongly encouraged to update WordPress core to the latest available patched version and ensure automatic updates are enabled where appropriate. Customers with automatic updates enabled should receive the applicable update automatically. However, we recommend verifying the currently running WordPress version to ensure the security update has been successfully applied. We will continue to monitor the situation and provide further updates if required. If you need assistance or have any concerns, please reach us via live chat or via a case. Additional information: https://wordpress.org/news/2026/08/wordpress-7-0-4-release/ https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-8vr3-7mxf-gx8w
We are currently investigating an issue affecting a subset of our servers in the us-west-1 region. Our systems engineers have been engaged and are working to restore service as quickly as possible. We appreciate your patience. If you have any questions or concerns. Please contact us via live chat or case.
A high-severity reflected XSS vulnerability, CVE-2026-64638, has been identified in the WordPress login interface. Exploitation requires a victim to visit a specially crafted URL and, under specific conditions, could potentially lead to PHP code execution. Impacted versions: WordPress 4.7 – 7.0.2 (every release on every branch) WordPress 4.6 and earlier — end of life, no patch available Fixed versions: WordPress 7.0.3 WordPress 6.9.6 WordPress 6.8.7 Equivalent minor releases on every remaining supported branch back to 4.7 Recommended Action Customers are strongly encouraged to update WordPress core and ensure automatic security updates are enabled where appropriate. Since exploitation requires user interaction, customers should also remain vigilant against phishing attempts and avoid clicking suspicious or unsolicited links. Customers with automatic security updates enabled should receive the applicable update automatically; however, we recommend verifying the currently running WordPress version. There is currently no reported evidence of widespread exploitation in the wild. We will continue to monitor the situation and provide further updates if required. If you need assistance or have any concerns, please contact our Support team.
Our Engineers are investigating an interruption in service affecting cloudhost-2915341.us-midwest-1.nxcli.net & cloudhost-2915335.us-midwest-1.nxcli.net. We understand the inconvenience this may cause and truly appreciate your patience while we resolve the issue. If you have any questions or concerns, please feel free to reach out to our support team via Live Chat or by opening a Support Case.