Monitoring - Beginning September 29, Pantheon identified malicious activity in which an attacker gained control of a customer website and used it to target platform resources.
Activity from the compromised site attempted to exploit a Linux kernel vulnerability (CVE-2026-53362) on platform application hosts, and some sites may have briefly experienced interruptions as a result.
We have taken the following actions:
- Disabled and deleted the affected site.
- Accelerated the operating-system and kernel updates already in progress, bringing application hosts to a version that addresses this vulnerability.
- Deployed additional platform protections and monitoring.
We have notified the affected customer directly. The compromise was limited to that single site; based on the information available to us, we have found no evidence of platform-wide data exfiltration or that this activity exposed data belonging to other customers.
We are continuing to review platform activity and will update this advisory if that changes.
How to protect your site:
Attackers most often gain control of a site through outdated or unmaintained code. Keeping your site current is the most effective protection. We strongly encourage all customers to keep CMS core, plugins, and themes fully updated, remove and delete sites and code you no longer use, and review user and credential access. If you notice unexpected code, deployments, or changes on your site, contact Pantheon Support.
We will post updates here as more information becomes available. If you have questions, please contact Pantheon Support.
Oct 01, 2026 - 12:38 PDT
Activity from the compromised site attempted to exploit a Linux kernel vulnerability (CVE-2026-53362) on platform application hosts, and some sites may have briefly experienced interruptions as a result.
We have taken the following actions:
- Disabled and deleted the affected site.
- Accelerated the operating-system and kernel updates already in progress, bringing application hosts to a version that addresses this vulnerability.
- Deployed additional platform protections and monitoring.
We have notified the affected customer directly. The compromise was limited to that single site; based on the information available to us, we have found no evidence of platform-wide data exfiltration or that this activity exposed data belonging to other customers.
We are continuing to review platform activity and will update this advisory if that changes.
How to protect your site:
Attackers most often gain control of a site through outdated or unmaintained code. Keeping your site current is the most effective protection. We strongly encourage all customers to keep CMS core, plugins, and themes fully updated, remove and delete sites and code you no longer use, and review user and credential access. If you notice unexpected code, deployments, or changes on your site, contact Pantheon Support.
We will post updates here as more information becomes available. If you have questions, please contact Pantheon Support.
Oct 01, 2026 - 12:38 PDT
Customer Sites
Operational
Dashboard
Operational
Global CDN
Operational
Spinup Operations
Operational
Workflow Operations
Operational
Support Tickets
Operational
Support Chat
Operational
Terminus Operations
Operational
Site Certificate Provisioning
Operational
Billing Operations
Operational
Autopilot
Operational
Git
Operational
Front-End Sites (Beta)
Operational
Content Publisher (Public Preview)
Operational
Operational
Degraded Performance
Partial Outage
Major Outage
Maintenance
Scheduled Maintenance
Routine Maintenance Impacting Site Management Operations Oct 13, 2026 18:00-19:00 PDT
As part of the upcoming 10/13 routine maintenance window, updates to two systems will result in limited service interruptions:
1. Site management workflow systems: We will update the systems that process deployments, database operations, and other site management workflows. These workflows will be temporarily interrupted, and jobs queued before the maintenance window may fail.
2. Next.js request-routing service: We will update the security settings for the service that routes requests to Next.js sites. Next.js sites may experience a brief interruption while this work is completed.
We recommend avoiding deployments and other site management workflows during the maintenance window. While we do not anticipate any impact to uptime for WordPress or Drupal sites during this maintenance window, Next.js sites may experience a brief interruption.
Posted on Oct 13, 2026 - 18:00 PDT
1. Site management workflow systems: We will update the systems that process deployments, database operations, and other site management workflows. These workflows will be temporarily interrupted, and jobs queued before the maintenance window may fail.
2. Next.js request-routing service: We will update the security settings for the service that routes requests to Next.js sites. Next.js sites may experience a brief interruption while this work is completed.
We recommend avoiding deployments and other site management workflows during the maintenance window. While we do not anticipate any impact to uptime for WordPress or Drupal sites during this maintenance window, Next.js sites may experience a brief interruption.
Posted on Oct 13, 2026 - 18:00 PDT