Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.7

CVE-2026-63090: ProFTPD mod_sftp Module Allows Code Execution

CVE-2026-63090 CVE-2026-63090
Summary

ProFTPD's SFTP module has a bug that can be exploited by authorized users to execute malicious code. This is a concern because it could allow attackers to take control of your server. To protect your system, update ProFTPD to the latest version, specifically 1.3.9c or 1.3.10rc3 and later.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
proftpd proftpd < 1.3.9c
Original title
ProFTPD mod_sftp Heap Buffer Overflow via SFTP Packet Reassembly
Original description
ProFTPD before 1.3.9c and 1.3.10rc3 contains a heap-based buffer overflow vulnerability in the mod_sftp module that allows authenticated low-privilege attackers to achieve arbitrary code execution by sending crafted SFTP packet fragments exceeding the 16 KB reassembly buffer in the fxp.c component. Attackers can supply oversized fragments to trigger an incorrectly conditioned reallocation, corrupt pool freelist metadata, overwrite the root_fs BSS global pointer to reference a fake filesystem struct, and redirect pr_fsio_stat() to system() via a crafted RENAME request.
nvd CVSS3.1 8.8
nvd CVSS4.0 8.7
Vulnerability type
CWE-122 Heap-based Buffer Overflow
Published: 20 Jul 2026 · Updated: 22 Jul 2026 · First seen: 20 Jul 2026