Pantheon Operations status is Operational

Wed 15
Thu 16
Fri 17
Sat 18
Sun 19
Mon 20
Tue 21
now

Pantheon Operations Customer Sites

Wed 15
Thu 16
Fri 17
Sat 18
Sun 19
Mon 20
Tue 21
now

Pantheon Operations Global CDN

Wed 15
Thu 16
Fri 17
Sat 18
Sun 19
Mon 20
Tue 21
now

Pantheon Operations Workflow Operations

Wed 15
Thu 16
Fri 17
Sat 18
Sun 19
Mon 20
Tue 21
now

Pantheon Operations Terminus Operations

Wed 15
Thu 16
Fri 17
Sat 18
Sun 19
Mon 20
Tue 21
now
Last updated 1 minute ago from official status page. Learn more

You're checking on Pantheon Operations - but is your own site converting?

Outages aren't the only thing that costs you visitors. Get a visual audit that shows exactly where your site loses conversions. Free, takes 2 minutes.

Audit Your Website Free →

Active Incidents

No active incidents

Recently Resolved Incidents

Site availability issues
Started 20 Jul 2026 21:09:52 (2 days ago), resolved 22 Jul 2026 10:27:23 (3 hours ago)
Major Incident
Resolved
Customer Sites
Workflow Operations
Terminus Operations

We're investigating site availability issues affecting workflows. This may impact your ability to push code, create environments, or run scheduled tasks. Our engineers are actively working on a fix, and we'll post updates here regularly.

WordPress 7.0.2 wp2shell
Started 20 Jul 2026 19:26:50 (2 days ago), resolved 21 Jul 2026 21:33:38 (16 hours ago)
Major Incident
Resolved
Global CDN

Summary On July 17, 2026, the WordPress security team disclosed two chained vulnerabilities in WordPress core, publicly referred to as "wp2shell":

  • CVE-2026-60137 — a SQL injection issue in WordPress core (WP_Query / author__not_in).
  • CVE-2026-63030 — a REST API batch-route confusion issue which, chained with the above, can lead to unauthenticated remote code execution.

Who is affected This affects specific versions of WordPress core:

  • 6.9.x — affected by both issues (RCE-capable). Patched in 6.9.6.
  • 7.0.x — affected by both issues (RCE-capable). Patched in 7.0.2.
  • 6.8.x — affected by the SQL injection issue only (not the full RCE chain). Patched in 6.8.6.

Sites already on 6.8.6 / 6.9.6 / 7.0.2 or later, or on versions prior to 6.8, are not affected by this chain.

Why it matters Chained together, these vulnerabilities can allow an unauthenticated attacker to execute code against a vulnerable site.

Pantheon’s immutable containers prevent the deployment of webshells, bitcoin miners, or other exploits that leverage a downloaded payload in production environments. However, SQL Injection can still be used to deface or hijack sites.

Because working exploits are publicly available, we expect attack volume to rise.

What you should do — action required Update WordPress core to a patched version as soon as possible — 7.0.2, 6.9.6, or 6.8.6 depending on your branch — from your Pantheon Dashboard or via Terminus. Updating core is the definitive fix. See the WordPress 7.0.2 Security Release note: https://docs.pantheon.io/release-notes/2026/07/wordpress-7-0-2

What Pantheon is doing

  • We are actively monitoring platform traffic for exploitation attempts targeting the affected REST API endpoint.
  • We have observed sites being probed for vulnerability and have actively mitigated against sources of scripted activity already.
  • We are deploying targeted mitigations at the network level to programmatically prevent exploit attacks across the platform and can confirm that released exploit code is being mitigated.
  • Will update this post with more information as those efforts progress.

Pantheon Operations Outage Survival Guide

A step-by-step guide to help you survive a Pantheon Operations outage
NaN%

    Pantheon Operations Components

    Wed 15
    Thu 16
    Fri 17
    Sat 18
    Sun 19
    Mon 20
    Tue 21
    now

    Pantheon Operations Customer Sites

    Wed 15
    Thu 16
    Fri 17
    Sat 18
    Sun 19
    Mon 20
    Tue 21
    now
    Site availability issues
    Started 20 Jul 2026 21:09:52 (2 days ago), resolved 22 Jul 2026 10:27:23 (3 hours ago)
    Major Incident
    Resolved
    Customer Sites
    Workflow Operations
    Terminus Operations

    We're investigating site availability issues affecting workflows. This may impact your ability to push code, create environments, or run scheduled tasks. Our engineers are actively working on a fix, and we'll post updates here regularly.

    Pantheon Operations Dashboard

    Wed 15
    Thu 16
    Fri 17
    Sat 18
    Sun 19
    Mon 20
    Tue 21
    now

    Pantheon Operations Global CDN

    Wed 15
    Thu 16
    Fri 17
    Sat 18
    Sun 19
    Mon 20
    Tue 21
    now
    WordPress 7.0.2 wp2shell
    Started 20 Jul 2026 19:26:50 (2 days ago), resolved 21 Jul 2026 21:33:38 (16 hours ago)
    Major Incident
    Resolved
    Global CDN

    Summary On July 17, 2026, the WordPress security team disclosed two chained vulnerabilities in WordPress core, publicly referred to as "wp2shell":

    • CVE-2026-60137 — a SQL injection issue in WordPress core (WP_Query / author__not_in).
    • CVE-2026-63030 — a REST API batch-route confusion issue which, chained with the above, can lead to unauthenticated remote code execution.

    Who is affected This affects specific versions of WordPress core:

    • 6.9.x — affected by both issues (RCE-capable). Patched in 6.9.6.
    • 7.0.x — affected by both issues (RCE-capable). Patched in 7.0.2.
    • 6.8.x — affected by the SQL injection issue only (not the full RCE chain). Patched in 6.8.6.

    Sites already on 6.8.6 / 6.9.6 / 7.0.2 or later, or on versions prior to 6.8, are not affected by this chain.

    Why it matters Chained together, these vulnerabilities can allow an unauthenticated attacker to execute code against a vulnerable site.

    Pantheon’s immutable containers prevent the deployment of webshells, bitcoin miners, or other exploits that leverage a downloaded payload in production environments. However, SQL Injection can still be used to deface or hijack sites.

    Because working exploits are publicly available, we expect attack volume to rise.

    What you should do — action required Update WordPress core to a patched version as soon as possible — 7.0.2, 6.9.6, or 6.8.6 depending on your branch — from your Pantheon Dashboard or via Terminus. Updating core is the definitive fix. See the WordPress 7.0.2 Security Release note: https://docs.pantheon.io/release-notes/2026/07/wordpress-7-0-2

    What Pantheon is doing

    • We are actively monitoring platform traffic for exploitation attempts targeting the affected REST API endpoint.
    • We have observed sites being probed for vulnerability and have actively mitigated against sources of scripted activity already.
    • We are deploying targeted mitigations at the network level to programmatically prevent exploit attacks across the platform and can confirm that released exploit code is being mitigated.
    • Will update this post with more information as those efforts progress.

    Pantheon Operations Spinup Operations

    Wed 15
    Thu 16
    Fri 17
    Sat 18
    Sun 19
    Mon 20
    Tue 21
    now

    Pantheon Operations Workflow Operations

    Wed 15
    Thu 16
    Fri 17
    Sat 18
    Sun 19
    Mon 20
    Tue 21
    now
    Site availability issues
    Started 20 Jul 2026 21:09:52 (2 days ago), resolved 22 Jul 2026 10:27:23 (3 hours ago)
    Major Incident
    Resolved
    Customer Sites
    Workflow Operations
    Terminus Operations

    We're investigating site availability issues affecting workflows. This may impact your ability to push code, create environments, or run scheduled tasks. Our engineers are actively working on a fix, and we'll post updates here regularly.

    Pantheon Operations Support Tickets

    Wed 15
    Thu 16
    Fri 17
    Sat 18
    Sun 19
    Mon 20
    Tue 21
    now

    Pantheon Operations Support Chat

    Wed 15
    Thu 16
    Fri 17
    Sat 18
    Sun 19
    Mon 20
    Tue 21
    now

    Pantheon Operations Terminus Operations

    Wed 15
    Thu 16
    Fri 17
    Sat 18
    Sun 19
    Mon 20
    Tue 21
    now
    Site availability issues
    Started 20 Jul 2026 21:09:52 (2 days ago), resolved 22 Jul 2026 10:27:23 (3 hours ago)
    Major Incident
    Resolved
    Customer Sites
    Workflow Operations
    Terminus Operations

    We're investigating site availability issues affecting workflows. This may impact your ability to push code, create environments, or run scheduled tasks. Our engineers are actively working on a fix, and we'll post updates here regularly.

    Pantheon Operations Site Certificate Provisioning

    Wed 15
    Thu 16
    Fri 17
    Sat 18
    Sun 19
    Mon 20
    Tue 21
    now

    Pantheon Operations Billing Operations

    Wed 15
    Thu 16
    Fri 17
    Sat 18
    Sun 19
    Mon 20
    Tue 21
    now

    Pantheon Operations Autopilot

    Wed 15
    Thu 16
    Fri 17
    Sat 18
    Sun 19
    Mon 20
    Tue 21
    now

    Pantheon Operations Git

    Wed 15
    Thu 16
    Fri 17
    Sat 18
    Sun 19
    Mon 20
    Tue 21
    now

    Pantheon Operations Front-End Sites (Beta)

    Wed 15
    Thu 16
    Fri 17
    Sat 18
    Sun 19
    Mon 20
    Tue 21
    now

    Pantheon Operations Content Publisher (Public Preview)

    Wed 15
    Thu 16
    Fri 17
    Sat 18
    Sun 19
    Mon 20
    Tue 21
    now
    Stay ahead of Pantheon Operations outages
    Sign up to create a custom dashboard to monitor the services you rely on. 3,000+ services supported.