AlbHost Service Status - Notice history

All systems operational

AlbHost Service Status

Other Notifications - Operational

Public Website - Operational

100% - uptime
01.07.2026 · 100%01.08.· 100%30.09.· 100%
01.07.2026
01.08.2026
30.09.2026

Core Network - Operational

100% - uptime
01.07.2026 · 100%01.08.· 100%30.09.· 100%
01.07.2026
01.08.2026
30.09.2026

API Services - Operational

100% - uptime
01.07.2026 · 100%01.08.· 100%30.09.· 100%
01.07.2026
01.08.2026
30.09.2026

KVM Node 1 - Operational

100% - uptime
01.07.2026 · 100%01.08.· 100%30.09.· 100%
01.07.2026
01.08.2026
30.09.2026

KVM Node 2 - Operational

100% - uptime
01.07.2026 · 100%01.08.· 100%30.09.· 100%
01.07.2026
01.08.2026
30.09.2026

KVM Node 3 - Operational

100% - uptime
01.07.2026 · 100%01.08.· 100%30.09.· 100%
01.07.2026
01.08.2026
30.09.2026

KVM Node 4 - Operational

100% - uptime
01.07.2026 · 100%01.08.· 100%30.09.· 100%
01.07.2026
01.08.2026
30.09.2026

KVM Node 5 - Operational

100% - uptime
01.07.2026 · 100%01.08.· 100%30.09.· 100%
01.07.2026
01.08.2026
30.09.2026

KVM Node 6 - Operational

100% - uptime
01.07.2026 · 100%01.08.· 100%30.09.· 100%
01.07.2026
01.08.2026
30.09.2026

KVM Node 7 - Operational

100% - uptime
01.07.2026 · 100%01.08.· 100%30.09.· 100%
01.07.2026
01.08.2026
30.09.2026

KVM Node 8 - Operational

100% - uptime
01.07.2026 · 100%01.08.· 100%30.09.· 100%
01.07.2026
01.08.2026
30.09.2026

KVM Node 9 - Operational

100% - uptime
01.07.2026 · 100%01.08.· 100%30.09.· 100%
01.07.2026
01.08.2026
30.09.2026

KVM Node 10 - Operational

100% - uptime
01.07.2026 · 100%01.08.· 100%30.09.· 100%
01.07.2026
01.08.2026
30.09.2026

KVM Node 11 - Operational

100% - uptime
01.07.2026 · 100%01.08.· 100%30.09.· 100%
01.07.2026
01.08.2026
30.09.2026

KVM Node 12 - Operational

100% - uptime
01.07.2026 · 100%01.08.· 100%30.09.· 100%
01.07.2026
01.08.2026
30.09.2026

Notice history

01.09.2026

No notices reported this month

01.08.2026

Security Incident – Password Reset Required
  • Resolved
    UTC
    Resolved

    Dear Customers,

    As a final precautionary measure, we will live migrate customer virtual machines from the affected hypervisors to newly deployed, clean hypervisors. This process is designed to minimise disruption and will not require customers to reinstall or reconfigure their VPS.

    Once all virtual machines have been safely migrated, the affected hypervisors will be fully wiped and reinstalled from clean installation media before being returned to service.

    No action is required from customers during this process. Existing VPS data, configurations and IP addresses will remain unchanged.

    We have not identified confirmed evidence that customer VPS instances were accessed or modified as part of this incident. The migration and rebuild are being performed as an additional security precaution to ensure the integrity of our infrastructure.

    With these remediation measures now underway, we are closing this incident as resolved. We will continue internal monitoring and security reviews as part of our normal operations.

    Thank you for your patience and understanding.

    Kind regards,
    AlbHost Support.

  • Identified
    UTC
    Identified

    Update – Root Cause Confirmed by Virtualizor

    Virtualizor has now confirmed that this incident resulted from a BGP hijack affecting part of the Softaculous/Virtualizor infrastructure between 28 August 2026 at approximately 20:57 UTC and 30 August 2026 at approximately 06:10 UTC.

    During this period, internet traffic intended for Virtualizor’s update infrastructure was diverted to an attacker-controlled server. The attacker obtained a technically valid TLS certificate, meaning affected update connections did not produce certificate warnings.

    Virtualizor has confirmed that a malicious update package was delivered to a small number of installations. It has also confirmed that its update client did not cryptographically verify update packages at the time, allowing the modified package to be accepted.

    The timing of the malicious execution observed on our infrastructure matches the incident window published by Virtualizor. Out of our 34 hypervisor nodes:

    • Five nodes received the malicious package.

    • No indicators of compromise have been identified on the other 29 nodes at this time.

    • One of the five affected nodes showed additional manual attacker activity after the initial automated infection.

    • We have not found confirmed evidence that customer VPS instances were accessed or modified.

    The affected nodes have been isolated. Virtualizor API credentials have been reset and restricted, unauthorised access has been removed, and additional infrastructure credentials are being rotated. All five affected hypervisors will be rebuilt from clean installation media.

    The unauthorised BGP announcement has ended and normal routing to Virtualizor’s infrastructure has been restored. However, our remediation and forensic review remain ongoing.

    As a precaution, we continue to advise all customers to change their AlbHost account password, VPS root or administrator passwords, and any passwords reused elsewhere. Customers should also review their VPS user accounts and SSH authorized_keys files for anything unfamiliar.

    Virtualizor’s official disclosure is available here:

    https://www.virtualizor.com/blog/security-incident-bgp-hijacking/

    We will publish another update when the rebuild and investigation have been completed.

  • Investigating
    UTC
    Investigating

    Hello,

    WWe have identified a security incident involving our Virtualizor infrastructure. Evidence of compromise was found on 5 of our 34 hypervisor nodes. We are continuing a full investigation across all nodes.

    The affected systems contained unauthorised software with root-level access. We are isolating the affected hosts, removing malicious persistence, rotating infrastructure credentials, and reviewing system, network and SSH activity. Every confirmed affected host will be completely rebuilt from clean media.

    At this time, we have no confirmed evidence that individual customer VPS instances were accessed. However, because account credentials may have been exposed, we strongly recommend that all customers take the following precautions:

    • Change your customer account and control-panel password.

    • Change the root or administrator password for every VPS.

    • Review /root/.ssh/authorized_keys and other users’ SSH key files for unfamiliar entries.

    • Remove any SSH keys you do not recognise.

    • Change the same password anywhere else if it was reused.

    • Enable two-factor authentication wherever available.

    Use new, unique passwords that have never previously been used. Do not send passwords or private keys to anyone claiming to represent our company.

    Our investigation is ongoing, and we will publish further updates as verified information becomes available.

    We sincerely apologise for the concern and disruption this incident may cause. Protecting customer systems and providing transparent updates remain our highest priorities.

01.07.2026

Scheduled Maintenance – Hypervisor Security Updates (CVE-2026-53359)
  • Completed
    12.07.2026 at 6:20 PMUTC
    Completed
    12.07.2026 at 6:20 PMUTC

    Maintenance has been completed successfully. All hypervisors have now been updated with the latest security patches addressing CVE-2026-53359.

    No further maintenance related to this security update is planned. We appreciate your patience and understanding throughout this maintenance window.

    Thank you for choosing AlbHost.

  • Update
    12.07.2026 at 1:45 PMUTC
    Update
    12.07.2026 at 1:45 PMUTC

    Maintenance is currently in progress. Approximately 90% of our hypervisors have been successfully upgraded. We will continue updating the remaining hypervisors until the maintenance has been completed.

  • Update
    11.07.2026 at 7:17 PMUTC
    Update
    11.07.2026 at 7:17 PMUTC

    Maintenance is currently in progress. Approximately 80% of our hypervisors have been successfully upgraded. We will continue updating the remaining hypervisors until the maintenance has been completed.

  • Update
    10.07.2026 at 11:31 PMUTC
    Update
    10.07.2026 at 11:31 PMUTC

    Maintenance is currently in progress. Approximately 70% of our hypervisors have been successfully upgraded with the latest security patches addressing CVE-2026-53359. Upgrade activities will resume tomorrow as we continue updating the remaining hypervisors until maintenance has been completed.

  • Update
    10.07.2026 at 10:37 PMUTC
    Update
    10.07.2026 at 10:37 PMUTC

    Maintenance is currently in progress. Approximately 50% of our hypervisors have been successfully upgraded. We will continue updating the remaining hypervisors until the maintenance has been completed.

  • In progress
    10.07.2026 at 10:00 PMUTC
    In progress
    10.07.2026 at 10:00 PMUTC

    Maintenance is currently in progress. Approximately 30% of our hypervisors have been successfully upgraded. We will continue updating the remaining hypervisors until the maintenance has been completed.

  • Planned
    10.07.2026 at 9:35 PMUTC
    Planned
    10.07.2026 at 9:35 PMUTC

    Dear Customers,

    To ensure the continued security and stability of our infrastructure, we will be performing scheduled maintenance across all KVM hypervisors to apply the latest Linux kernel security updates addressing CVE-2026-53359 ("Januscape"), a recently disclosed KVM/x86 guest-to-host escape vulnerability.

    For more information about the vulnerability, please refer to the National Vulnerability Database (NVD):
    https://nvd.nist.gov/vuln/detail/CVE-2026-53359

    During the maintenance, each hypervisor will be updated and rebooted individually. As a result, virtual machines hosted on the affected hypervisor will experience a brief interruption while the update is being applied.

    This maintenance is being carried out as a proactive security measure to ensure the continued security, stability, and reliability of our virtualization platform.

    We apologize for any inconvenience this may cause and appreciate your patience and understanding. Progress updates will be posted on this status page throughout the maintenance window.

    Kind regards,
    AlbHost Team

01.07.2026 to 01.09.2026

Next