CVE-2026-63090: ProFTPD before 1.3.9c and 1.3.10rc3 contains a heap-based buffer overflow vulnerability in the mod_sftp module that allows authenticated low-privilege attackers to achieve arbitrar
ProFTPD before 1.3.9c and 1.3.10rc3 contains a heap-based buffer overflow vulnerability in the mod_sftp module that allows authenticated low-privilege attackers to achieve arbitrary code execution by sending crafted SFTP packet fragments exceeding the 16 KB reassembly buffer in the fxp.c component. Attackers can supply oversized fragments to trigger an incorrectly conditioned reallocation, corrupt pool freelist metadata, overwrite the root_fs BSS global pointer to reference a fake filesystem struct, and redirect pr_fsio_stat() to system() via a crafted RENAME request.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-63090
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-630900.46% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 37% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-63090 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] ProFTPD: Multiple vulnerabilitiescert-bund
Recent advisories for ProFTPD
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- high[UPDATE] [high] ProFTPD: Vulnerability allows SQL injectioncert-bund · 2026-07-27
- high[UPDATE] [high] ProFTPD: Vulnerability allows bypassing security measures and file manipulationcert-bund · 2026-07-22
- high[NEW] [high] ProFTPD: Multiple vulnerabilitiescert-bund · 2026-07-21
- mediumCVE-2026-63091: ProFTPD before 1.3.9c and 1.3.10rc3 contains a signed integer overflow vulnerability in the mo…nvd · 2026-07-20
- medium[NEW] [medium] ProFTPD: Vulnerability allows denial of servicecert-bund · 2026-07-20
- highCVE-2026-53994: ProFTPD mod_sftp contains a heap-based buffer overflow reachable by an authenticated SFTP user…nvd · 2026-07-18
More from NVD Recent CVEs
- unknownCVE-2026-55735: Improper Verification of Cryptographic Signature in ueberauth guardian allows an unauthenticat…2026-08-01
- unknownCVE-2026-55734: Allocation of Resources Without Limits or Throttling vulnerability in ueberauth guardian (Guar…2026-08-01
- unknownCVE-2026-55733: Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of se…2026-08-01
- unknownCVE-2026-54894: Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of se…2026-08-01
- mediumCVE-2026-67355: guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the …2026-08-01