We will be carrying out urgent security maintenance across 1/3 of our VPS nodes to address a critical security matter and keep our infrastructure protected.
A reboot of all VPS instances hosted on the impacted nodes will take place during this maintenance. As a result, customers should expect a brief service interruption of up to 15 minutes per VPS while their server reboots. No further impact is expected beyond this short reboot.
🕐 The maintenance is scheduled for July 7th, 2026, from 11:15 PM UTC and is expected to be completed on July 8th, 2026 by 3:00 AM UTC.
No action is required from clients. All virtual servers will automatically come back online once they have been rebooted.
This maintenance affects VPS nodes only. All of our other services remain fully operational and are not impacted in any way.
Impacted cluster nodes:
🇩🇪 Frankfurt (fra01)
🇳🇱 Amsterdam (ams01)
🇫🇮 Helsinki (hel01)
If you experience any issues following the maintenance window, please don't hesitate to reach out to our support team for assistance. You may contact us through tickets in the Client Area, Telegram support bot or over e-mail.
Thank you for your understanding as we work to keep our infrastructure and customer servers secure.
--
The urgent security maintenance is now fully completed. All cluster nodes have been patched, rebooted, and are operating normally.
Rather than taking everything down at once, we worked through each cluster node one by one - this kept simultaneous downtime across affected nodes to a minimum and let us apply the necessary changes precisely on each host. Because of the nature of the fix, some nodes required structural changes and took longer to process than others, so thanks for bearing with us while that was done carefully across the fleet.
This addressed a recently disclosed Linux kernel vulnerability, Januscape (CVE-2026-53359). In simple terms: it's a flaw in KVM, the technology that keeps each virtual server isolated from the physical host and from other customers on the same machine. Under specific conditions, it could let a malicious VM break out of that isolation and compromise the host, if nested virtualization was enabled on the host. It had gone unnoticed for ~16 years (!) and affects both Intel and AMD systems.
We have no indication it was ever exploited on our infrastructure — this was a proactive patch applied as soon as fixes landed, which required a kernel update and reboot on each node.
No action is required from clients. Everything is back online.
If you run into any issues, reach out to our support team and we'll be glad to help.