<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"  xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<title>Vservs B.V. - Internet Service Provider - News</title>
<description>Vservs B.V. - Internet Service Provider - News</description>
<link>https://vservs.com/client-area/?cmd=news</link>
<atom:link href="https://vservs.com/client-area/?cmd=news&amp;action=rss" rel="self" type="application/rss+xml" />
<item>
	<title>Important WordPress Security Update</title>
	<link>https://vservs.com/client-area/?cmd=news&amp;action=view&amp;id=72</link>
        <guid>https://vservs.com/client-area/?cmd=news&amp;action=view&amp;id=72</guid>
	<pubDate>Thu, 13 Aug 2026 00:00:00 +0200</pubDate>
	<description><![CDATA[On August 6, 2026, a security vulnerability in WordPress Core was disclosed under CVE-2026-64638, also referred to as XSS2Shell.

The vulnerability affects the WordPress login screen and, under certain circumstances, can be exploited through a reflected XSS attack. If a logged-in WordPress administrator is successfully targeted, the vulnerability could ultimately allow PHP code to be executed within the affected website.

Due to the potential impact, we strongly recommend that WordPress users treat this security update with high priority.

Which WordPress installations are affected?

The vulnerability affects WordPress versions that are currently within the WordPress security backport range, from WordPress 4.7.0 through 7.0.2.

WordPress has released security updates addressing this vulnerability.

If you use WordPress, please verify that your installation has been updated to a version containing the security fix.

What should you do?

We recommend that you:

* update WordPress Core to the latest available secure version as soon as possible;
* check older or no longer actively used WordPress installations as well;
* update plugins and themes where possible;
* verify that both your website and WordPress administration area operate correctly after the update.

If automatic WordPress Core updates are enabled, the security update may already have been installed automatically. Nevertheless, we recommend checking the currently installed WordPress version.

Very old WordPress installations

WordPress installations older than version 4.7 fall outside the current WordPress security backport policy. Although the underlying vulnerability may also exist in older installations, separate security updates may not be provided for these versions.

If you are still using such an outdated WordPress version, we strongly recommend upgrading the website to a current and supported WordPress release.

No simple workaround

There is no simple workaround for this vulnerability, such as blocking a specific URL or WordPress REST API endpoint.

The recommended solution is to install the official WordPress Core security update.

Need assistance?

If you are unsure which WordPress version your website is using or would like assistance with the update, please feel free to contact us.

Vservs is happy to assist you in checking and keeping your website secure.

Vservs B.V.
Hosting & Server Solutions]]></description>
</item>
<item>
	<title>Platform Update: PHP 7 End-of-Life &amp; New Security Policy</title>
	<link>https://vservs.com/client-area/?cmd=news&amp;action=view&amp;id=71</link>
        <guid>https://vservs.com/client-area/?cmd=news&amp;action=view&amp;id=71</guid>
	<pubDate>Sun, 26 Jul 2026 00:00:00 +0200</pubDate>
	<description><![CDATA[Important Technical Changes to Our Hosting Platform

To keep our hosting platform secure, stable and fully compatible with the latest software, we will be implementing several important technical changes over the coming period.

Please take a moment to read the information below, as it may affect your website or application.

⸻

PHP 7.x has reached End of Life

PHP 7.x has been end-of-life for quite some time and no longer receives security updates from the PHP Foundation.

In addition, more and more software vendors now require PHP 8.x or higher. A recent example is Roundcube Webmail for DirectAdmin, which now requires at least PHP 8.x.

What does this mean for you?

If your website, webshop or application is still running on PHP 7.x, we strongly recommend upgrading to a supported PHP version as soon as possible.

Continuing to use PHP 7.x may result in:

* No further security updates.
* Inability to install future software updates.
* Increasing compatibility issues.
* Greater exposure to security vulnerabilities.

We recommend using PHP 8.2 or PHP 8.3, depending on your application.

⸻

Linux Kernel Security Updates Will Be Activated Immediately

Over the past months we have seen a significant increase in Linux kernel security updates, and we expect this trend to continue.

A Linux kernel update only becomes active after the server has been rebooted.

Previously, we often contacted customers to schedule a convenient reboot window. Due to the increasing number of critical security updates, this is no longer practical.

New Policy

Whenever a Linux kernel security update is installed, we will reboot the server as soon as possible to ensure the update becomes active immediately.

This minimizes the time servers remain vulnerable after security patches have been installed.

What can you expect?

In most cases, very little.

A controlled reboot generally takes only 1 to 2 minutes. For most websites and email services, this interruption is so brief that it is barely noticeable.

Our priority is to keep your hosting environment secure while minimizing service interruption.

⸻

Our Commitment

Cybersecurity threats continue to evolve rapidly. By keeping our infrastructure up to date and activating security updates immediately, we can continue providing a secure, stable and reliable hosting platform.

If you are unsure whether your website or application supports PHP 8.x, please contact our support team. We will be happy to help you prepare for the transition.]]></description>
</item>
<item>
	<title>Critical WordPress Security Update – Immediate Action Recommended</title>
	<link>https://vservs.com/client-area/?cmd=news&amp;action=view&amp;id=69</link>
        <guid>https://vservs.com/client-area/?cmd=news&amp;action=view&amp;id=69</guid>
	<pubDate>Wed, 22 Jul 2026 00:00:00 +0200</pubDate>
	<description><![CDATA[Two critical security vulnerabilities have been disclosed in WordPress Core, identified as CVE-2026-63030 and CVE-2026-60137. Together these vulnerabilities are commonly referred to as wp2shell.

When chained together, these vulnerabilities allow an unauthenticated remote attacker to achieve remote code execution (RCE) on a default WordPress installation. This could potentially lead to full compromise of a website and its hosting environment.

Who is affected?

Any website running a vulnerable version of WordPress Core may be affected.

We strongly recommend verifying the WordPress version running on all your websites.

Patched versions

The vulnerabilities have been fixed in:

* WordPress 7.1 Beta 2
* WordPress 7.0.2
* WordPress 6.9.5
* WordPress 6.8.6

Please update your website to one of these versions (or newer) as soon as possible.

Temporary mitigation

If an immediate update is not possible, consider the following temporary mitigations until the update can be installed:

* Block the following REST API endpoints at your web server or Web Application Firewall (WAF):
    * /wp-json/batch/v1
    * rest_route=/batch/v1
* Temporarily disable the WordPress REST API where possible.

These measures are temporary only and do not replace installing the official security update.

Vservs Recommendation

We strongly advise all WordPress users to verify whether their installations are vulnerable and apply the latest security updates immediately.

If your website is hosted on a Vservs Managed Hosting platform and you require assistance, our support team is ready to help.]]></description>
</item>
<item>
	<title>Important Changes for .RU, .РФ and .SU Domains Starting September 1, 2026</title>
	<link>https://vservs.com/client-area/?cmd=news&amp;action=view&amp;id=67</link>
        <guid>https://vservs.com/client-area/?cmd=news&amp;action=view&amp;id=67</guid>
	<pubDate>Thu, 21 May 2026 00:00:00 +0200</pubDate>
	<description><![CDATA[The Russian domain registries are introducing new legal requirements for all .RU, .РФ and .SU domain names.

Starting September 1, 2026, all domain holders will be required to complete electronic identification through the Russian government platform Gosuslugi.

These changes affect both Russian and international domain owners.

What does this mean?

Without successful verification through Gosuslugi, .RU, .РФ and .SU domains may no longer be fully manageable.

This means it may no longer be possible to:

* renew domains
* change nameservers or DNS settings
* update registrant information
* register new .RU/.SU/.РФ domains

If a domain cannot be renewed, it will eventually expire and may be lost.

Who is affected?

These rules also apply to customers outside Russia.

For international domain owners, verification may be difficult or even impossible without:

* a Russian digital identity
* Russian documentation
* or a local presence in Russia

What should customers do now?

We strongly recommend that customers with .RU, .РФ or .SU domains take action well before the deadline.

Step 1 – Review your domains

Check which .RU, .РФ and .SU domains you currently use.

Determine:

* which domains are actively used
* which are business critical
* which may no longer be necessary

Step 2 – Choose a solution

There are currently three possible options:

Option A – Russian registrant

Register the domain under:

* a Russian company
* a Russian partner
* or a Russian individual with Gosuslugi verification

Option B – Trustee / Local Presence Service

Trustee solutions will become available where a local compliant party officially manages the domain on your behalf.

Our registrar has announced that additional information and pricing will be provided later.

Option C – Use an alternative extension

Consider making important websites and email services available under alternative extensions such as:

* .COM
* .NET
* .EU
* .DE

This helps reduce dependency on future Russian regulations.

Important deadline

Deadline: September 1, 2026

After this date, unverified .RU, .РФ and .SU domains may become partially or fully unmanageable.

We strongly advise customers not to wait until the last moment.

Need assistance?

If you own .RU, .РФ or .SU domains and would like advice about the best solution, please contact our support team.

We are happy to assist with:

* reviewing your domain portfolio
* discussing alternatives
* preparing for the new regulations
* future trustee solutions]]></description>
</item>
<item>
	<title>Information about SSL certificates and new security standards (effective March 12, 2026)</title>
	<link>https://vservs.com/client-area/?cmd=news&amp;action=view&amp;id=65</link>
        <guid>https://vservs.com/client-area/?cmd=news&amp;action=view&amp;id=65</guid>
	<pubDate>Tue, 27 Jan 2026 00:00:00 +0100</pubDate>
	<description><![CDATA[Dear customer,

We would like to inform you about a change in global SSL/TLS security standards, effective March 12, 2026. This change applies to all certificate authorities and affects the technical validity of SSL certificates, not your subscription or pricing.

---

### What will change from March 12, 2026?
From this date, SSL certificates must be reissued more frequently during their subscription term. This is a global security measure that applies to all publicly trusted SSL/TLS certificates.

Important to note:
- SSL certificates will continue to be sold as annual or multi-year subscriptions
- Your SSL subscription and pricing remain unchanged
- Reissuance takes place within the existing term

---

### What does this mean for you?
For most customers, nothing changes in practice.

- If your domain name and DNS are managed by Vservs  
  → We will handle validation and reissuance fully automatically via our DNS systems.

- If your domain and/or DNS is hosted externally (with another provider)  
  → In some cases you may need to perform a validation step yourself, such as adding a DNS record or file. We will notify you in advance when action is required.

⚠️  Fully managed SSL validation for domains using Vservs DNS  
⚠️ External DNS or registration may require manual validation

If your SSL certificate is managed by Vservs, we will handle reissuance automatically where possible, without website downtime.

---

### Short FAQ

Do I need to take action on March 12, 2026?  
No. Your SSL will remain active and be reissued automatically within your existing subscription.

Will pricing or contract terms change?  
No. SSL subscriptions remain annual or multi-year with no changes.

Why is this being introduced?  
This is a global security measure to improve internet safety and respond faster to security incidents.

---

### Summary
- ✔️ Effective date: March 12, 2026
- ✔️ No pricing changes
- ✔️ No action required for most customers
- ✔️ Fully automated for domains and DNS via Vservs
- ✔️ External DNS may require customer validation

If you have questions or would like us to review your setup, please contact us.

Kind regards,  
Vservs B.V]]></description>
</item>
<item>
	<title>Important information about DirectAdmin licenses, MariaDB versions and Pro Pack</title>
	<link>https://vservs.com/client-area/?cmd=news&amp;action=view&amp;id=64</link>
        <guid>https://vservs.com/client-area/?cmd=news&amp;action=view&amp;id=64</guid>
	<pubDate>Thu, 22 Jan 2026 00:00:00 +0100</pubDate>
	<description><![CDATA[Dear customer,

We would like to inform you about an update in the classification of our DirectAdmin licenses, to ensure clarity about the configuration you are using and the available upgrade options.

---

### DirectAdmin Legacy
Customers with an existing DirectAdmin license have been assigned to DirectAdmin Legacy.  
This configuration remains fully supported and can continue to be used, with the following characteristics:

- MariaDB 10.6 LTS
- Unlimited accounts and domains
- Enterprise support for MariaDB until August 23, 2029
- No upgrade possible to MariaDB versions higher than 10.6

For many environments, MariaDB 10.6 remains stable and more than sufficient. You are free to continue using this configuration as long as it meets your requirements.

---

### Upgrade to newer MariaDB versions (with Pro Pack)
If you wish to use newer MariaDB versions (11.4 or higher), an upgrade of your DirectAdmin license is required.

An upgrade option is available in the client area to:
- DirectAdmin Lite + Pro Pack (max. 10 accounts / 50 domains)
- DirectAdmin Standard + Pro Pack (unlimited accounts & domains)

These modern licenses include the DirectAdmin Pro Pack, which provides additional features such as:
- Advanced backup and restore functionality
- Enhanced security and system features
- Extended tooling for professional and production environments
- Support for modern software stacks and future updates

---

### Frequently Asked Questions (FAQ)

Do I need to take action now?  
No. Your current environment will continue to operate as it does now. There is no mandatory upgrade.

Why is MariaDB limited to version 10.6 with DirectAdmin Legacy?  
DirectAdmin Legacy is based on a fixed, long-term supported configuration. Newer MariaDB versions require a modern DirectAdmin license type.

Is MariaDB 10.6 still secure and supported?  
Yes. MariaDB 10.6 is an LTS release with enterprise support until 23-08-2029.

What do I gain by upgrading?  
You gain access to newer MariaDB versions (11.4+) and the DirectAdmin Pro Pack, including advanced features and long-term compatibility.

Can I upgrade at a later time?  
Yes. The upgrade option will remain available in the client area.

---

### No action required
- Your current environment remains unchanged  
- There is no required upgrade  
- An upgrade is only needed if you want a newer MariaDB version or Pro Pack features  

If you have any questions or would like advice on which option best fits your situation, we are happy to assist you.

Kind regards,  
Vservs B.V.]]></description>
</item>
<item>
	<title>Christmas Greeting &amp; Holiday Schedule Vservs</title>
	<link>https://vservs.com/client-area/?cmd=news&amp;action=view&amp;id=63</link>
        <guid>https://vservs.com/client-area/?cmd=news&amp;action=view&amp;id=63</guid>
	<pubDate>Thu, 11 Dec 2025 00:00:00 +0100</pubDate>
	<description><![CDATA[Dear customer,

On behalf of the entire Vservs team, we want to thank you for your trust over the past year. We wish you and your loved ones a Merry Christmas and a happy, healthy and successful 2026!

Below you will find our availability during the Christmas holiday period.

⸻

Holiday Schedule & Availability

Holiday period:
• Starting Friday, December 19th, 2025 at 12:00 PM
• Until Monday, January 5th, 2026 at 09:00 AM

During this period we work with a limited schedule.

What we will handle

• Server and network outages (24/7 as always)
• Emergency cases
• New server orders
• New SSL orders

What continues automatically

• Domain registrations and renewals (fully automated)

What we cannot process during the holiday

• Website issues caused by customers – we will restore backups if needed
• General support tickets
• Non-urgent changes

Regular service resumes on January 5th, 2026 at 09:00 AM.

⸻

Thank you for your understanding and for choosing Vservs.
We wish you wonderful holidays and an excellent start to the new year!

Kind regards,
Vservs]]></description>
</item>
<item>
	<title>Please note the following domain price adjustments:</title>
	<link>https://vservs.com/client-area/?cmd=news&amp;action=view&amp;id=59</link>
        <guid>https://vservs.com/client-area/?cmd=news&amp;action=view&amp;id=59</guid>
	<pubDate>Wed, 19 Feb 2025 00:00:00 +0100</pubDate>
	<description><![CDATA[Please note the following domain price adjustments:

.biz > Register and Transfer €27,50 renew €30-
.work > Register and Transfer €20,- renew €25-]]></description>
</item>
</channel></rss>