Pantheon Operations
Update - We are continuing to monitor traffic patterns and adapt network-level mitigations in response.
Jul 21, 2026 - 06:43 PDT
Update - We can observe our mitigations denying an increasing volume of requests and are continuing to gather data to enhance our response.

We will provide an update Tuesday morning.

Jul 20, 2026 - 15:20 PDT
Monitoring - Summary
On July 17, 2026, the WordPress security team disclosed two chained vulnerabilities in WordPress core, publicly referred to as "wp2shell":

- CVE-2026-60137 — a SQL injection issue in WordPress core (WP_Query / author__not_in).
- CVE-2026-63030 — a REST API batch-route confusion issue which, chained with the above, can lead to unauthenticated remote code execution.

Who is affected
This affects specific versions of WordPress core:

- 6.9.x — affected by both issues (RCE-capable). Patched in 6.9.6.
- 7.0.x — affected by both issues (RCE-capable). Patched in 7.0.2.
- 6.8.x — affected by the SQL injection issue only (not the full RCE chain). Patched in 6.8.6.

Sites already on 6.8.6 / 6.9.6 / 7.0.2 or later, or on versions prior to 6.8, are not affected by this chain.

Why it matters
Chained together, these vulnerabilities can allow an unauthenticated attacker to execute code against a vulnerable site.

Pantheon’s immutable containers prevent the deployment of webshells, bitcoin miners, or other exploits that leverage a downloaded payload in production environments. However, SQL Injection can still be used to deface or hijack sites.

Because working exploits are publicly available, we expect attack volume to rise.

What you should do — action required
Update WordPress core to a patched version as soon as possible — 7.0.2, 6.9.6, or 6.8.6 depending on your branch — from your Pantheon Dashboard or via Terminus. Updating core is the definitive fix. See the WordPress 7.0.2 Security Release note: https://docs.pantheon.io/release-notes/2026/07/wordpress-7-0-2

What Pantheon is doing
- We are actively monitoring platform traffic for exploitation attempts targeting the affected REST API endpoint.
- We have observed sites being probed for vulnerability and have actively mitigated against sources of scripted activity already.
- We are deploying targeted mitigations at the network level to programmatically prevent exploit attacks across the platform and can confirm that released exploit code is being mitigated.
- Will update this post with more information as those efforts progress.

Jul 20, 2026 - 12:26 PDT
Update - The fix remains stable, with no new issues detected.

We're continuing to monitor system metrics and logs to confirm the resolution holds. We'll post again once we have new findings.

Jul 20, 2026 - 21:53 PDT
Update - We are closely monitoring the recent fix and have not identified any new issues.

We will provide further updates as they become available.

Jul 20, 2026 - 16:29 PDT
Update - We are continuing to monitor for any further issues.
Jul 20, 2026 - 14:37 PDT
Monitoring - We've deployed a fix for the workflow availability issues and expect systems to recover shortly. Engineers are actively monitoring the rollout to confirm that pushing code, creating environments, and running scheduled tasks return to normal.
Jul 20, 2026 - 14:36 PDT
Investigating - We're investigating site availability issues affecting workflows. This may impact your ability to push code, create environments, or run scheduled tasks. Our engineers are actively working on a fix, and we'll post updates here regularly.
Jul 20, 2026 - 14:09 PDT
Customer Sites Operational
Dashboard Operational
Global CDN Partial Outage
Spinup Operations Operational
Workflow Operations Operational
Support Tickets Operational
Support Chat Operational
Terminus Operations Operational
Site Certificate Provisioning Operational
Billing Operations Operational
Autopilot Operational
Git Operational
Front-End Sites (Beta) Operational
Content Publisher (Public Preview) Operational
Operational
Degraded Performance
Partial Outage
Major Outage
Maintenance
Customer Site Availability
Fetching
Dashboard Response Time
Fetching
Jul 21, 2026

Unresolved incident: WordPress 7.0.2 wp2shell.

Jul 20, 2026

Unresolved incident: Site availability issues.

Jul 19, 2026

No incidents reported.

Jul 18, 2026

No incidents reported.

Jul 17, 2026

No incidents reported.

Jul 16, 2026

No incidents reported.

Jul 15, 2026

No incidents reported.

Jul 14, 2026
Completed - The scheduled maintenance has been completed.
Jul 14, 19:00 PDT
In progress - Scheduled maintenance is currently in progress. We will provide updates as necessary.
Jul 14, 18:00 PDT
Scheduled - During this maintenance window, there will be a temporary interruption of the following services:

1. Dashboard: May experience slowness or be intermittently accessible
2. Workflows: Deploys, backups, and database operations may be delayed
3. Certificate Services: New certificate issuance may be temporarily impacted

We recommend you avoid starting workflows during the maintenance window. We apologize for any inconvenience this may cause and assure you that our team will work diligently to minimize any disruption.

We do not anticipate any impact to your site(s) uptime during this maintenance window.

We understand the importance of our services to your business, and we assure you that our team will complete the maintenance as quickly as possible. We will also keep you informed of any updates or changes during the maintenance process. Should you have any questions or concerns, please reach out to our customer support team via chat or email us at Pantheon Helpdesk.

Jul 9, 07:38 PDT
Jul 13, 2026

No incidents reported.

Jul 12, 2026

No incidents reported.

Jul 11, 2026
Resolved - This incident has been resolved. The Pantheon Dashboard is performing normally, and loading times remain completely stable.
Jul 11, 14:33 PDT
Monitoring - A fix has been implemented and we are monitoring the results.
Jul 10, 15:03 PDT
Update - Investigation into the Pantheon Dashboard performance degradation is ongoing.
For critical support outside the dashboard interface, email helpdesk@pantheon.io immediately.

Next update: Between 30 minutes and 3 hours.

Jul 10, 10:57 PDT
Investigating - We are investigating reports of slow load times and degraded performance within the Pantheon Dashboard.
Traffic to live sites is routing normally and is not impacted by this event.

Our Engineering team is actively working to identify the root cause and restore full Dashboard functionality.
If you are unable to access the Dashboard to submit a ticket, please email us directly at helpdesk@pantheon.io for critical, time-sensitive deployments.

Next update: 30 minutes.

Jul 10, 09:33 PDT
Jul 10, 2026
Jul 9, 2026

No incidents reported.

Jul 8, 2026

No incidents reported.

Jul 7, 2026

No incidents reported.