A high-severity vulnerability tracked as CVE-2026-63090 affects ProFTPD's mod_sftp module and can allow a low-privilege authenticated user to achieve remote code execution. Public reporting describes the bug as a heap-based buffer overflow triggered by crafted SFTP or SSH authentication traffic, with one account tying exploitation to malformed SFTP packet fragment reassembly in fxp.c and another linking it to improper bounds checking in sftp_ssh2_userauth_callback. In both cases, the flaw can corrupt heap memory and potentially give an attacker control of the ProFTPD process, creating a path to data theft, persistence, and lateral movement.
Affected versions cited across disclosures include multiple ProFTPD 1.3.8 and 1.3.9 releases prior to patched builds, with fixes reported in versions such as 1.3.8c, 1.3.9b, 1.3.9c, and 1.3.10rc3 depending on branch and advisory. The issue carries a CVSS 8.8 rating, and while no active exploitation was reported at disclosure, defenders were urged to patch immediately, disable mod_sftp where it is not required, and restrict SSH/SFTP access to trusted users and networks to reduce exposure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Sources disclose CVE-2026-63090 as a high-severity heap-based buffer overflow in ProFTPD's mod_sftp module that can allow remote code execution by an authenticated low-privilege attacker. The reports describe crafted SFTP or SSH authentication input as the trigger and note affected ProFTPD versions across multiple release branches.
Reference content states that the ProFTPD mod_sftp heap buffer overflow tracked as CVE-2026-63090 was remediated in newer versions. One source recommends upgrading to 1.3.9c or 1.3.10rc3 or later, while another says fixes were issued in 1.3.8c and 1.3.9b.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.