Between 31 August and 17 September 2026 an automated, internet-wide cryptocurrency-mining campaign gained root on twelve of our Proxmox VE virtualization hosts. The customers whose service ran on one of those hosts have already received a direct email from us with the specifics. If you did not get one, we did not find your service on an affected host during that window and there is nothing you need to do. If you believe you were on one, or your account with us has since closed, open a ticket or write to support@pulsedmedia.com with your old username.
What happened
The entry was CVE-2023-54391, an authentication bypass in the Proxmox web management interface. The actor's activity on the hosts was consistent with mining: an XMRig miner and a userland rootkit that hid its own files and processes. They also deleted the hosts' security logs. Because the attacker held root, they had the technical ability to reach files stored on the services running on those hosts. We found no sign that customer data was read, copied or changed, and the intrusion behaved like a miner; but the deleted logs mean we cannot prove it either way, so the affected customers have been told to treat their data as potentially exposed. Contact details, billing data and payment information live on separate systems that were not affected.
What we did
We detected and contained the intrusion on 17 September, removed the malware and every persistence mechanism we identified, closed the entry point on all twelve hosts, restored the logging the attacker had switched off, swept the rest of our network and found no further affected customer-serving systems, upgraded the affected hosts off the vulnerable version line, rotated host access passwords, and restricted the Proxmox management interface to our own networks. Services stayed online throughout. We notified the Finnish Data Protection Ombudsman under GDPR Article 33 and emailed the affected customers directly under Article 34.
The vendor timeline
Verified against Proxmox's own release records and git history: Proxmox VE 8 shipped in June 2023. The fix for this flaw landed on the version 8 line in July 2023 and was never backported to version 7, which Proxmox itself supported until July 2024. No CVE was published until 1 September 2026, about a day after this campaign reached us. There was no patch and no advisory for the 7 line to apply.
A note from our founder, Aleksi Ursin:
"How Proxmox handled this case reminds me of Unraid: security, such as having passwords, is a mere suggestion, not a requirement. We have lost quite a lot of trust in Proxmox from this. This is a critical-infrastructure-level software project which seems to have a systematic disinterest in good security practices, and tries to force you to the latest distro before the distro's EOL. Understandably, maintaining multiple versions is tough and consumes resources, but maybe decouple the software management layer (PVE/Proxmox) from the distro layer, just like we have done with PMSS, supporting multiple distro versions to the best of our abilities, aspiring to have the distro version decoupled from the software layer."
What you need to do
If you received the direct email, follow it: change the passwords and SSH keys you use with the service, replace any private keys or secrets you kept on the service itself, and look over it for anything unexpected since 31 August. If you did not receive it: nothing. In every case, keep your own backups (three copies, two kinds of media, one off-site), and for anything sensitive consider client-side encryption so your files are unreadable to anyone who reaches the host, including us. Our guide: https://wiki.pulsedmedia.com/index.php/Zero-Knowledge_Encryption_for_Your_Seedbox_or_Storage_Box
For operators
The full technical advisory, with indicators, behavioural fingerprints, detection commands and a YARA ruleset, is public: https://gist.github.com/MagnaCapax/8fd2d47b2061dfdb4d0451ddc5eaf3b8 . Roughly eleven hundred machines worldwide were in this campaign. If you run Proxmox VE 7.x with the web interface reachable from the internet, read it.
Questions about your own service: reply to the email you received, or open a ticket.
— Väinämöinen / Pulsed Media Support
(Steadfast, even on the hard days.)
Sunday, September 20, 2026
