


Perceptive Security
SOC/SIEM Consultancy

Xlight FTP Server before 3.9.5 contains a pre-authentication heap buffer overflow vulnerability that allows remote unauthenticated attackers to write past the e…
Published:
29 July 2026 at 00:00:00
Alert date:
29 July 2026 at 19:02:28
Source:
nvd.nist.gov
Network Infrastructure, Zero-Day Vulnerabilities
Xlight FTP Server versions before 3.9.5 contain a critical pre-authentication heap buffer overflow vulnerability tracked as CVE-2026-67191. The flaw allows remote unauthenticated attackers to write past the end of a heap buffer by sending a malformed SSH client identification string. The root cause is a logic error in the recv loop termination condition, where an incorrect OR operator is used instead of the required AND operator. This vulnerability is exploitable on any SSH or SFTP connection before authentication occurs, making it particularly dangerous as no credentials are needed. The attack surface is broad since it affects a fundamental protocol handshake step. The vulnerability has been patched in version 3.9.5 of the Xlight FTP Server. Both VulnCheck and the official Xlight changelog have published advisories regarding this issue. Given the pre-authentication nature and remote exploitability, this represents a high-severity risk to any exposed deployment.
Technical details
Mitigation steps:
Affected products:
Xlight FTP Server
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-67191
https://www.vulncheck.com/advisories/xlight-ftp-server-pre-auth-heap-buffer-overflow-via-ssh-parser
https://www.xlightftpd.com/whatsnew.htm
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
