Monitoring - Beginning September 29, Pantheon identified malicious activity in which an attacker gained control of a customer website and used it to target platform resources.

Activity from the compromised site attempted to exploit a Linux kernel vulnerability (CVE-2026-53362) on platform application hosts, and some sites may have briefly experienced interruptions as a result.

We have taken the following actions:
- Disabled and deleted the affected site.
- Accelerated the operating-system and kernel updates already in progress, bringing application hosts to a version that addresses this vulnerability.
- Deployed additional platform protections and monitoring.

We have notified the affected customer directly. The compromise was limited to that single site; based on the information available to us, we have found no evidence of platform-wide data exfiltration or that this activity exposed data belonging to other customers.
We are continuing to review platform activity and will update this advisory if that changes.

How to protect your site:
Attackers most often gain control of a site through outdated or unmaintained code. Keeping your site current is the most effective protection. We strongly encourage all customers to keep CMS core, plugins, and themes fully updated, remove and delete sites and code you no longer use, and review user and credential access. If you notice unexpected code, deployments, or changes on your site, contact Pantheon Support.

We will post updates here as more information becomes available. If you have questions, please contact Pantheon Support.

Oct 01, 2026 - 12:38 PDT
Customer Sites Operational
Dashboard Operational
Global CDN Operational
Spinup Operations Operational
Workflow Operations Operational
Support Tickets Operational
Support Chat Operational
Terminus Operations Operational
Site Certificate Provisioning Operational
Billing Operations Operational
Autopilot Operational
Git Operational
Front-End Sites (Beta) Operational
Content Publisher (Public Preview) Operational
Operational
Degraded Performance
Partial Outage
Major Outage
Maintenance

Scheduled Maintenance

Routine Maintenance Impacting Site Management Operations and IAM bindings Oct 13, 2026 18:00-19:00 PDT

1. Workflow infrastructure update: There will be a temporary interruption of site management workflows. Specifically, deployments and database operations will be interrupted. In addition, jobs queued in advance of the window will fail during the window.

2. IAM binding cleanup: This may cause brief downtime on the tenant-router Cloud Run service.

We recommend you avoid starting workflows during the maintenance window. We apologize for any inconvenience this may cause and assure you that our team will work diligently to minimize any disruption.

We do not anticipate any impact to PHP site(s) uptime during this maintenance window. Next.js sites may experience brief downtime.

We understand the importance of our services to your business, and we assure you that our team will complete the maintenance as quickly as possible. We will also keep you informed of any updates or changes during the maintenance process. Should you have any questions or concerns, please reach out to our customer support team via chat or email us at helpdesk@pantheon.io.

Posted on Oct 01, 2026 - 04:58 PDT
Customer Site Availability
Fetching
Average Dashboard Load Time
Fetching

Oct 1, 2026

Unresolved incident: Security Advisory: Malicious Activity Affecting Platform Hosts.

Sep 30, 2026

Resolved - Some sites experienced brief interruptions while we responded to an issue affecting appserver stability. We completed a rolling security upgrade and restart of appservers across all regions. All known affected sites have recovered, and the platform is operating normally.

We are continuing to monitor the platform and complete follow-up hardening work.
We apologize for the disruption and appreciate your patience.

Sep 30, 09:53 PDT

Sep 29, 2026

No incidents reported.

Sep 28, 2026

No incidents reported.

Sep 27, 2026

No incidents reported.

Sep 26, 2026

No incidents reported.

Sep 25, 2026

No incidents reported.

Sep 24, 2026

No incidents reported.

Sep 23, 2026

No incidents reported.

Sep 22, 2026

No incidents reported.

Sep 21, 2026

No incidents reported.

Sep 20, 2026

No incidents reported.

Sep 19, 2026

No incidents reported.

Sep 18, 2026

No incidents reported.

Sep 17, 2026

No incidents reported.