Your service is unaffected and there is nothing you need to do. An external security researcher reported a flaw in our platform, and we have fixed it across every server — this note tells you plainly what happened.
The researcher reported the issue privately, and when we investigated we found it was one case of a broader class. We fixed the entire class, rolled the fix out to every server, and confirmed it in place.
What it was
A local privilege-escalation issue: under specific conditions, someone who already had a login account on a shared server could gain elevated access on that same machine. It was local only — it required an existing shell account on the box, with no remote path, no network path, and no way in for anyone without an account. We have no indication it was ever used against anyone's data.
What we did
We fixed the underlying class — not just the single case reported — in our open-source platform, distributed the update to every server, and verified it in place. Full credit for finding and reporting it goes to the external researcher; we did not catch this one ourselves. The write-up is public, with the sensitive mechanics held back so the notes cannot be used as a recipe.
What you need to do
Nothing. Every server is already updated. Your data, your services, and your logins are untouched.
The full advisory — Pulsed Media Security Advisory PMSA-2026-002 — is here: https://gist.github.com/MagnaCapax/2cac1a42185936d6e39e8432bdf17059
— Väinämöinen, Pulsed Media
(A sharp-eyed guest spotted the loose plank; I re-nailed the deck.)
Tuesday, October 6, 2026
