Partial Outage of Avoro VMs and Control Panel Functionality

Incident Report for dataforest

Postmortem

Following the incident on Tuesday, September 1, 2026, we want to provide a comprehensive postmortem regarding the root cause, our immediate response, and the resulting infrastructure upgrades.

Incident Discovery & Scope

On Tuesday morning, we detected unauthorized access to 2 of our approximately 50 Avoro virtualization hosts (epyc7513-1 and epyc9374f-8).

Because this intrusion exploited a design flaw unique to this specific legacy setup, all other products (such as PHP-Friends vServer, the dataforest cloud, and our internal systems) operating in completely separate clusters were never at risk.

By analyzing network traffic externally – completely outside the compromised systems – and monitoring active processes on the hosts, we confirmed the intrusion was strictly a known crypto-mining script. It exploited a Proxmox zero-day vulnerability disclosed just 90 minutes prior. We verified there was no ransomware, and no customer data or disk images were accessed or exfiltrated.

Immediate Response & Control Panel Disconnect

The Avoro customer area (our control panel based on WHMCS) historically required external communication with the cluster. For failover purposes, exactly the two affected nodes were equipped with a public IPv4 address to handle this traffic.

Once we identified the intrusion, we completely locked down the Proxmox management VLAN. Although our analysis showed no manipulation of the shutdown sequence, we deliberately cut power to the compromised nodes as a precaution. We initiated this without prior notification to avoid unnecessary risks, but updated this status page within a few seconds once the power was cut. Locking down the VLAN and isolating the hosts successfully neutralized the threat, but temporarily severed communication with the Avoro customer area.

Service Recovery

Our Ceph storage cluster allowed us to quickly restart all affected virtual machines on unaffected replacement hardware within 5 to 30 minutes.

To restore the customer area functionalities, we assigned a required communication IP address to a different host. We then systematically re-established access strictly limited to our internal dependency systems (Avoro customer area, ISO storage, template storage, VNC, backup systems) to ensure no vulnerabilities were exposed during the recovery process.

Root Cause & Legacy Architecture

The exploitation of the zero-day vulnerability was only possible due to two legacy conditions in the Avoro cluster:

  • Public IP Accessibility: As mentioned, two specific nodes were publicly accessible to communicate with the customer area. Our modern infrastructure is strictly isolated behind VPNs and firewalls.
  • Update Dependencies: Complex dependencies involving historically grown third-party modules in the customer area prevented us from applying host updates instantly. (Note: The core customer area software itself is always up to date with security patches).

Infrastructure Rebuild & Security Enhancements

Wednesday: Management and our technical teams outlined a permanent architectural overhaul for the Avoro customer area and the Avoro cluster.

Thursday: We officially commenced the comprehensive rebuild. We are deploying a brand-new Proxmox cluster strictly behind our modern VPN standards and setting up a new staging instance to replace legacy third-party modules, in order to ultimately support the latest Proxmox version. To free up resources for the upcoming migrations, all Avoro VM products have temporarily been set to "out of stock".

Friday: We started working on this postmortem.

Customer Impact & Upcoming Maintenances

Since our external network traffic analysis ruled out any data exfiltration, you do not need to change your passwords, SSH keys, or take any other action regarding your server data.

To finalize the remediation, we will announce the following maintenances via Statuspage:

  • Mid September: Comprehensive maintenance to deploy the new Avoro customer area environment.
  • Late September: VM migrations to the newly built Avoro cluster will start. We will perform live migrations wherever technically possible, but cannot guarantee zero-downtime migrations for all individual VMs.

We stand for an open error culture and acknowledge that the legacy setup of the affected hosts did not meet our current strict security standards. Thank you for your continued trust. If you have any further technical questions, our management is available via the ticket system.

Posted Sep 06, 2026 - 23:59 CEST

Resolved

VNC access was restored at 22:37, followed by the reinstallation feature at 01:00. All previously affected control panel functionality has now been restored.
Thank you for bearing with us while we worked to restore these services.
Posted Sep 02, 2026 - 01:10 CEST

Update

Basic control panel functionality was restored at 18:50, including starting and stopping VMs as well as booting from mounted ISOs. Creating and restoring backups is also possible again.
We are continuing to work on restoring VNC access and the reinstallation feature.
Posted Sep 01, 2026 - 19:44 CEST

Monitoring

All affected VMs have been back online on replacement hardware for the past 10 minutes. Restoration was completed in well under 30 minutes, significantly faster than the previously estimated recovery time of up to two hours.
We are now working to restore the control panel functionality.
Posted Sep 01, 2026 - 13:38 CEST

Identified

Two of our Avoro VM hosts, epyc7513-1 and epyc9374f-8, are currently experiencing an outage. The majority of Avoro VMs are not affected by the host outage itself. Customers can check the customer area to see whether any of their VMs are running on the affected hosts.

VM control functions such as starting, stopping, and reinstalling are currently unavailable for all Avoro customers, as this functionality depends on the affected hosts.

Affected VMs will be restarted on replacement hardware as soon as possible. We expect this process to take up to two hours. Individual VMs may be restored significantly earlier, as they will be brought back online sequentially.

We will share further details as soon as they become available.
Posted Sep 01, 2026 - 13:01 CEST
This incident affected: General Services (Avoro CP & Support) and Datacenter MC-FRA01 (Virtual Servers).