GitHub is reporting degraded performance via their status page this morning:
https://www.githubstatus.com/
Per the page, this problem may be affecting Pull Requests, Issues, Copilot, Actions, Webhooks, and API requests, among other services. Customers should follow the GitHub status page for the latest information.
resolved
This incident has been resolved.
Service disruption at the Phoenix Data Center
Started August 13, 2026 at 12:53 PM UTC · 2d 17h
OutageCritical incident
Affected components
PHX Network
investigating
We are currently investigating network issues affecting servers in our Phoenix Data Center. During this time, you may experience connectivity disruptions or degraded performance.
Our engineers are actively working to identify the root cause and restore service stability as quickly as possible.
If you have any questions or require assistance, please contact us via chat or open a support case through portal.liquidweb.com
We appreciate your patience and understanding while we work to resolve this issue. Thank you.
identified
Dear Valued Customer,
We are currently responding to a critical facilities issue affecting our Phoenix, Arizona data center.
A major chiller equipment failure at the facility has significantly reduced cooling capacity, resulting in elevated temperatures and an increased risk of service disruption and potential hardware impact.
The data center provider is actively working to restore normal cooling operations. Replacement work is underway, with current estimates indicating repairs may take 10–16 hours or longer.
Additional information regarding the facility incident is available on the data center provider's status page:
https://status.phoenixnap.com/incidents/dnjp5pfv2mmh
Our teams are closely monitoring conditions and working directly with the data center provider to minimize customer impact. To protect customer infrastructure and reduce the risk of hardware damage or data loss, we may need to perform controlled shutdowns of affected systems if facility temperatures reach unsafe levels. Where necessary, we will prioritize orderly shutdown procedures to protect the underlying infrastructure.
Customers with services hosted within the affected Phoenix facility should prepare for potential service interruptions while remediation efforts continue.
We understand the seriousness of this situation and the impact an extended disruption may have on your business. We will continue to provide updates as conditions change and additional information becomes available. We sincerely apologize for the disruption and appreciate your patience as we work to protect your infrastructure and restore normal operations.
Sincerely,
Nexcess Support Team
identified
Dear Valued Customer,
Update: Our teams are continuing to work closely with our data center provider at the Phoenix location. Our data center teams and on-site vendors continue working to restore adequate cooling.
As part of our ongoing mitigation efforts, we are gracefully shutting down impacted systems where necessary to help protect customer data and reduce the risk of data corruption or hardware-related issues while temperatures remain elevated.
We apologize for the disruption and appreciate your patience as we work to protect your infrastructure and restore normal operations.
We will continue to provide updates as the situation progresses.
Sincerely,
Nexcess Support Team
identified
Dear Valued Customer,
We are continuing to work closely with our provider as they address the elevated temperatures at the Phoenix facility. Progress is being made, and temperatures are continuing to come down as cooling systems are restored and additional mitigation efforts are put in place.
We apologize for the disruption and appreciate your patience as we work to protect your infrastructure and restore normal operations. We will continue to provide updates as the situation progresses.
For the latest status and updates from the facility, please visit:
https://status.phoenixnap.com/incidents/dnjp5pfv2mmh
Sincerely,
Nexcess Support Team
monitoring
Internal ambient temperatures in our Phoenix, Arizona data center have continued to moderate and onsite Nexcess Engineers have begun to restore service to networking equipment and other services. Our Senior Engineering and Leadership teams are actively monitoring the situation and will continue to protect customer infrastructure and reduce the risk of hardware damage or data loss where necessary, however at this time customers should begin to see network service restoring to their environments.
monitoring
Our Nexcess Engineering teams continue working to restore all remaining systems and services in our Phoenix, Arizona data center. While significant progress has been made and many systems have returned to service, our teams are continuing to bring remaining infrastructure back online in a controlled and careful manner.
As systems and network services are restored, our Engineering and Operations teams are monitoring them very closely to confirm they remain stable and continue operating as expected. We are also actively watching environmental conditions and infrastructure health throughout the facility to reduce the risk of additional service disruption, hardware damage, or data loss.
Work will continue until all affected systems and services have been fully restored. Our Engineering and Leadership teams remain actively engaged, and we will continue to provide updates as restoration efforts progress and overall service stability is confirmed.
monitoring
Our Nexcess Engineering teams have successfully brought the majority of systems and services in our Phoenix, Arizona data center back online, and work continues actively to restore the remaining pending services.
For all restored systems, our teams are conducting thorough checks across the infrastructure to confirm complete stability and ensure there is no ongoing operational impact. Out of an abundance of caution, we continue to closely monitor facility environmental conditions and overall infrastructure health.
We will provide further updates in this space as restoration and verification efforts progress.
monitoring
Our Nexcess Engineering teams have brought the majority of systems and services in our Phoenix, Arizona data center back online, and work remains actively underway to restore the remaining pending services.
Over the past several hours, we have observed continued stability across all restored systems with no red flags identified. Out of an abundance of caution, our teams are continuing to perform ongoing checks and closely monitor facility environmental conditions alongside overall infrastructure health.
We will provide further updates in this space as restore and verification efforts progress.
monitoring
The vast majority of impacted servers have been brought online and are functional at this time. We continue to monitor the stability of the network to ensure normal operations.
Our engineers are still working on restoring functionality to the Cloud Sites Platform but are making progress. The root cause has been identified and progress is being made. Updates and more information regarding those efforts can be found on our Cloud Sites Status Page here: https://status.websitesettings.com/incidents/0l8hyyhr6v93
monitoring
We have restored all services and observed continued stability. We will keep a close eye on the platform and continue to update this page with any new developments.
resolved
All post-outage cleanup activities have been completed, and everything is working as expected. We will continue to monitor the environment, and this incident is now resolved.
Security Advisory: WordPress Security Update for CVE-2026-65640
Started August 12, 2026 at 3:44 PM UTC · Ongoing
Pending
investigating
A security vulnerability, CVE-2026-65640, has been identified in WordPress that could allow an authenticated Author-level or higher user to achieve remote code execution through a malicious file upload on sites using Imagick and Ghostscript.
The vulnerability has been addressed through updates across supported WordPress branches.
Patched Versions:
Customers should update to the following patched version for their respective WordPress branch:
7.0.4
6.9.7
6.8.8
6.7.7
6.6.7
6.5.10
6.4.10
6.3.10
6.2.11
6.1.12
6.0.14
5.9.16
5.8.15
5.7.17
5.6.19
5.5.20
5.4.21
5.3.23
5.2.26
5.1.24
5.0.27
4.9.31
4.8.30
4.7.35
Recommended Action:
Customers are strongly encouraged to update WordPress core to the latest available patched version and ensure automatic updates are enabled where appropriate.
Customers with automatic updates enabled should receive the applicable update automatically. However, we recommend verifying the currently running WordPress version to ensure the security update has been successfully applied.
We will continue to monitor the situation and provide further updates if required.
If you need assistance or have any concerns, please reach us via live chat or via a case.
Additional information:
https://wordpress.org/news/2026/08/wordpress-7-0-4-release/
https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-8vr3-7mxf-gx8w
A high-severity reflected XSS vulnerability, CVE-2026-64638, has been identified in the WordPress login interface. Exploitation requires a victim to visit a specially crafted URL and, under specific conditions, could potentially lead to PHP code execution.
Impacted versions
Impacted versions:
WordPress 4.7 – 7.0.2 (every release on every branch)
WordPress 4.6 and earlier — end of life, no patch available
Fixed versions:
WordPress 7.0.3
WordPress 6.9.6
WordPress 6.8.7
Equivalent minor releases on every remaining supported branch back to 4.7
Recommended Action
Customers are strongly encouraged to update WordPress core and ensure automatic security updates are enabled where appropriate. Since exploitation requires user interaction, customers should also remain vigilant against phishing attempts and avoid clicking suspicious or unsolicited links.
Customers with automatic security updates enabled should receive the applicable update automatically; however, we recommend verifying the currently running WordPress version.
There is currently no reported evidence of widespread exploitation in the wild. We will continue to monitor the situation and provide further updates if required.
If you need assistance or have any concerns, please contact our Support team.
VMware MT Service Degradation
Started August 1, 2026 at 1:34 AM UTC · 33m
OutageMajor incident
Affected components
VMware CloudVMware Private Cloud
investigating
We are investigating intermittent connectivity and increased latency affecting some services hosted in the VMware MT environment.
Our engineers are actively working to identify the cause and restore normal service as quickly as possible.
We appreciate your patience and understanding while we work to resolve this issue. If you have any questions or concerns, please open a support ticket or contact us via chat.
resolved
Service has been restored at this time, and the affected VMware MT-hosted services are operating normally.
Thank you for your patience and understanding while our teams worked to resolve this issue.
On July 17th Wordpress.org announced two critical remote code execution (RCE) vulnerabilities commonly known as WP2Shell. These vulnerabilities exist in Wordpress Core and allow an unauthenticated request to execute arbitrary code on the target website.
Customers running the Wordpress versions below are strongly advised to upgrade to latest version shown as soon as possible:
Wordpress 6.8.x; fixed in 6.8.6
WordPress 6.9.x; fixed in 6.9.5
WordPress 7.0.x; fixed in 7.0.2
WordPress 7.1 beta, fixed in 7.1 beta2
Source: https://wordpress.org/news/2026/07/wordpress-7-0-2-release/
Posted 2 minutes ago. Jul 17, 2026 - 21:44 EDT
identified
Our teams continue to work diligently to assess the impact of the recently disclosed WordPress Core vulnerabilities and verify that appropriate mitigation measures are in place. We remain actively engaged in our investigation and are monitoring the situation for any new developments.
We will continue to closely monitor the situation and take any additional steps necessary to maintain system security and stability. If you need assistance or have any concerns, please contact our Support team.
monitoring
Services have been restored, and websites are currently loading as expected. Our Network team is continuing to investigate the underlying cause and is actively monitoring the environment to ensure stability.
At this time, all services appear to be operating normally. If you experience any issues or need assistance, please contact our Support team.
identified
The issue has been identified and a fix is being implemented.
identified
We are continuing to work on a fix for this issue.
identified
Given the severity of this vulnerability, Liquid Web Systems Engineers have been proactively upgrading affected Wordpress applications across our fleet. Customers are still strongly encouraged to review their Wordpress websites and, if affected, to update to the patched version as soon as possible.
resolved
This incident has been resolved.
Power Outage in Phoenix, AZ
Started July 16, 2026 at 8:02 PM UTC · 4h 24m
OutageMajor incident
Affected components
DC4 - PHX
investigating
A subset of servers within our Phoenix, AZ data center lost power. Our on-site team is investigating.
monitoring
Primary power has been restored, and we are monitoring the situation.
resolved
This incident has been resolved.
Apache Service Disruption Following ModSecurity Update
Started July 15, 2026 at 9:35 PM UTC · 7d 21h
OutageMajor incident
Affected components
Cloud VPS HostingCloud Dedicated
investigating
We are investigating an issue affecting Apache services on our servers following a recent EasyApache ModSecurity update.
Customers on affected servers may experience websites being unavailable, HTTP errors, or connection timeouts.
Our Engineering team is currently working to restore services.
Need help? Chat with us or create a ticket via my.liquidweb.com.
We appreciate your patience and understanding while we work to restore normal service.
monitoring
A fix has been implemented, and our Engineering team is monitoring the affected servers to confirm Apache services remain stable.
resolved
This incident has been resolved.
Januscape Vulnerability (CVE-2026-53359)
Started July 9, 2026 at 2:34 PM UTC · 20d 4h
Pending
Affected components
Cloud VPS Hosting
investigating
Our team is currently assessing the impact and scope of Januscape Vulnerability (CVE-2026-53359), and its impact on servers in our fleet and the best way to apply patches to our hosting infrastructure.
We will be sending communications to any affected customers as we work to apply the necessary mitigations.
Next Steps:
Teams are currently in review of vulnerability; subsequent status updates will follow.
identified
Our teams are continuing to deploy the required security updates across affected systems in response to the Januscape Vulnerability (CVE-2026-53359). As part of this remediation, some systems require a controlled reboot to complete the patching process.
Following each reboot, we are validating system availability, service health, and network connectivity. Systems that do not return to service as expected are being actively investigated and restored by our operations teams.
We understand the importance of maintaining availability and are working carefully to complete this remediation while minimizing customer impact. Additional updates will be provided as patching and validation efforts continue.
resolved
The security updates have been applied across the Liquid Web fleet.
WHM login failures
Started July 8, 2026 at 9:49 PM UTC · 14h 10m
OutageMajor incident
Affected components
CPanel
investigating
It has been brought to our attention that a large subset of our cPanel customers are seeing an error message when attempting to log into WHM.
"Invalid License File. Incorrect authority delivering the license."
WebPros (cPanel) is aware of the issue and they are currently investigating.
We appreciate your patience as they work to resolve the issue.
monitoring
cPanel has been working on improving the performance of their licensing servers and implemented changes. We are seeing access to WHM and cPanel restored without intervention from support.
If you are still having issues please reach out to support and we will be happy to assist.
monitoring
WebPros has stated that the issue has been resolved and that servers should begin to renew licenses properly. If you are still experiencing issues logging in, feel free to contact us via chat or email and we can expedite the resolution.
resolved
We have observed continued stability, and the cPanel licence updates have gone smoothly so far.
If you need any further assistance, please do not hesitate to reach out to our Support team via chat or email.
Infrastucture down issues at Phoenix Data Center
Started July 2, 2026 at 4:49 AM UTC · 5h 48m
Pending
Affected components
DC4 - PHX
investigating
We are investigating issues affecting servers in our Phoenix Data Center. You may experience connectivity issues. Our Engineers currently investigating the issue to isolate the cause and restore stability.
Need help? Chat with us or create a case via my.liquidweb.com.
We appreciate your patience and understanding as we work to restore this service. Thank you.
identified
We are investigating an issue affecting connectivity between our Phoenix Data Center and internal services. We have identified that the issue is related to network connectivity with an upstream provider during a scheduled maintenance window.
At this time, customer-facing services are expected to remain accessible from public networks, and we have not identified a widespread impact to externally accessible services. Our Engineers are actively working with the upstream provider to restore full connectivity as quickly as possible.
Need help? Chat with us or create a case via my.liquidweb.com.
We appreciate your patience and understanding as we work to restore this service. Thank you.
monitoring
We are seeing continued improvement in network connectivity as the affected links begin to recover. All customer websites and servers remain online and accessible.
The scheduled maintenance is still in progress, and our Engineering team is actively monitoring the environment to ensure connectivity is fully restored. We will continue to provide updates as additional information becomes available.
Need help? Chat with us or create a case via my.liquidweb.com.
We appreciate your patience and understanding as we work to restore this service. Thank you.
resolved
We have been monitoring the situation, and everything has remained stable. This incident has now been resolved.
Security Advisory: Update Avada Builder and UpdraftPlus WordPress Plugins Immediately
Started June 26, 2026 at 5:23 AM UTC · 13d 8h
Pending
Affected components
InterWorx
investigating
We are advising all customers using WordPress to verify that the following plugins are updated to the latest available versions.
Recently disclosed vulnerabilities affect older versions of these plugins:
CVE-2026-6279 – Avada Builder (Fusion Builder) – Unauthenticated Remote Code Execution
Affected versions: 3.15.2 and earlier
CVE-2026-10795 – UpdraftPlus Backup Plugin – Authentication Bypass
Affected versions: 1.26.4 and earlier
These vulnerabilities may allow unauthenticated attackers to gain control of vulnerable WordPress sites and compromise WordPress user accounts if the plugins have not been updated to the latest available versions.
If your website uses either of these plugins, we strongly recommend that you:
Update the affected plugin(s) to the latest available version immediately.
Review your WordPress installation for any unexpected administrator accounts, plugins, or modified files.
Contact our Support team if you believe your website has been affected or if you need assistance reviewing your installation.
resolved
This advisory is now being closed.
We encourage our customers to ensure that any affected WordPress plugins have been updated to the latest available versions and continue following WordPress security best practices.
If you believe your website may have been impacted or require assistance, please contact our Support team.
Network Service Impact, Subset of Services, DC3
Started June 24, 2026 at 1:57 PM UTC · 2h 51m
OutageCritical incident
Affected components
LAN NetworkDC3 - LAN
investigating
We are aware of a network service event affecting a subset of customers in our DC3 Data Center in Lansing, Michigan. Liquid Web Network Engineers are currently engaged and working to restore service as quickly as possible. We will provide another update as soon as possible this morning with more information.
monitoring
Liquid Web Network Engineers have identified the cause and implemented a fix, network traffic has resumed at this time to affected areas of the data center. We are actively monitoring the environment. We will provide another update as soon as possible this morning with more information.
resolved
This incident has been resolved.
Monitoring Service Degradation
Started June 18, 2026 at 5:11 PM UTC · 44m
Pending
investigating
We are currently experiencing a partial degradation in our monitoring and alerting system. Some monitoring components are intermittently unable to generate or relay alerts as expected.
Our engineering teams are actively investigating the issue to identify the cause and restore full monitoring functionality.
We appreciate your patience and understanding while we work to resolve this issue. If you have any questions or concerns, please open a support ticket or contact us via chat.
Monitoring Service Degradation
Started June 6, 2026 at 1:20 PM UTC · 1d 4h
IssuesMinor incident
investigating
We are currently experiencing a service degradation affecting our monitoring infrastructure and monitoring ticket integration.
As a result, some monitoring alerts may be delayed in being generated, delivered, or escalated to our teams. Customer services themselves are not impacted by this issue; however, the delay in alert processing may result in slower detection and response to service-related incidents.
Our engineers are actively investigating and working to restore normal monitoring performance as quickly as possible.
We appreciate your patience and understanding while we work to resolve this issue. If you have any questions or concerns, please open a support ticket or contact us via chat.
monitoring
Our teams have implemented a fix for the issue affecting the monitoring system and are continuing to monitor the service to ensure stability.
We will provide additional updates if any further issues are identified.
Thank you for your patience.
resolved
This incident has been resolved.
Phone System Issues
Started May 27, 2026 at 7:58 PM UTC · 3h 54m
OutageMajor incident
Affected components
Phone
investigating
We are investigating an issue preventing customers from reaching support via Phone.
Please use Live Chat or open a Support Case at my.liquidweb.com for immediate assistance while we restore the phone service.
We appreciate your patience and understanding as we work to restore this service. Thank you.
monitoring
Our phone system is now back online, and agents should be able to connect and accept calls.
We will continue to monitor the system to ensure stability.
Thank you for your continued patience.
A recently disclosed vulnerability (CVE-2026-48172) in the LiteSpeed user-end cPanel plugin allows an unprivileged user to escalate to root privileges in plugin versions between v2.3 and v2.4.4. This issue has been classified as high severity. Public reports suggest the vulnerability was being exploited in the wild in May 2026, and indicators of compromise have been published. On May 19th cPanel issued a separate update which disabled and removed the plugin. This vulnerability is patched in v2.4.7 of the user-end plugin and v5.3.1.0 of the WHM plugin (which bundles the user-end plugin).
Reference:
https://nvd.nist.gov/vuln/detail/CVE-2026-48172
https://blog.litespeedtech.com/2026/05/21/security-update-for-litespeed-cpanel-plugin/
https://support.cpanel.net/hc/en-us/articles/40599423437079-Security-LiteSpeed-plugin-automatically-removed-during-nightly-update-May-19-2026
Status
Our security and operations teams are completing an assessment of our infrastructure and will force a upcp update today for all systems we are able to reach. We plan to review for Indicators of Compromise following the updates.
Customer Guidance
Customers managing their own systems or using unmanaged services should ensure they have applied the latest security updates or have removed the plugin. Customers should also review their systems for indicators of compromise using the information provided in the LiteSpeed blog article.
Should you need any assistance or have any questions or concerns, you can reach us through the following channels:
Live Chat via the Customer Portal: https://my.liquidweb.com
Email: [email protected]
We will continue monitoring this vulnerability and will provide updates if new information becomes available.
resolved
Status Update
Our security and operations teams completed the assessment of our infrastructure, which forcd a upcp update today for all systems we were able to reach. We also reviewed environments for the indicators of compromise noted in the LiteSpeed article below. We will address any findings via a support ticket. We are resolving this incident at this time.
Customer Guidance
Customers are strongly encouraged to ensure they are running the updated version of the LiteSpeed plugin and to review their systems for the indicators of compromise. If our team does not have access to your system because it is unmanaged, self-managed, or access has been updated but not shared with Liquid Web, then we would not have been able to reach your system in order to apply updates or check for indicators of compromise.
If you have any questions or concerns, you can reach us through the following channels:
Live Chat via the Customer Portal: https://my.liquidweb.com
Email: [email protected]
Issue Accessing Portal via login.liquidweb.com
Started May 24, 2026 at 4:47 PM UTC · 21h 24m
OutageMajor incident
Affected components
Management Portal
investigating
We are investigating an issue preventing customers from accessing the portal through login.liquidweb.com. Updates are forthcoming as more information becomes available.
Need help? Chat with us or contact Support for assistance.
We appreciate your patience and understanding as we work to restore portal access. Thank you.
investigating
We are continuing to investigate the issue impacting access to the portal through login.liquidweb.com.
While the site may be loading for some users, our teams are still reviewing the issue and working to confirm full service stability.
Updates will be provided as more information becomes available.
Thank you for your patience while we continue working toward a resolution.
monitoring
Access to the portal through login.liquidweb.com has been restored, and the site is now loading successfully.
Our teams have implemented a fix and are continuing to monitor the service to ensure stability.
We will provide additional updates if any further issues are identified.
Thank you for your patience while we worked to restore access.
resolved
This incident has been resolved.
Security Advisory: Linux Privilege Escalation Vulnerability (CVE-2026-31431)
Started May 11, 2026 at 10:12 PM UTC · 25d 23h
OutageMajor incident
Affected components
CPanelCloud VPS HostingCloud Dedicated
identified
A recently disclosed Linux vulnerability (CVE-2026-31431), sometimes referred to as “Copy Fail,” affects certain Linux distributions and may allow a local, unprivileged user to escalate privileges under specific conditions. This issue has been classified as high severity.
Status
Our security and operations teams have completed an assessment of our infrastructure and have applied all relevant vendor patches and mitigations to affected systems.
Impact
No evidence of exploitation has been identified within our environment
Systems under our management have been patched or otherwise mitigated
Customer Guidance
Customers managing their own systems or using unmanaged services should ensure they have applied the latest security updates provided by their Linux distribution and review any related vendor advisories.
We will continue monitoring this vulnerability and will provide updates if new information becomes available.
resolved
This incident has been resolved.
Let's Encrypt Service Interruption
Started May 8, 2026 at 8:56 PM UTC · 4h 19m
Pending
investigating
We have been made aware of an incident that is affecting Let's Encrypt. The third party SSL provider is currently not issuing SSL certificates as they investigate the issue further.
More information is available at at Let's Encrypts status page here: https://letsencrypt.status.io/
If you have any additional questions please reach out to our support team and we will be happy to assist
monitoring
Let's Encrypt has updated their status post indicating that they are resuming their typical issuance of certificates.
We will continue to monitor to see if there are any changes in their status going forward