top of page
perceptive_background_267k.jpg

Xlight FTP Server before 3.9.5 contains a pre-authentication heap buffer overflow vulnerability that allows remote unauthenticated attackers to write past the e…

Published:

29 juli 2026 om 00:00:00

Alert date:

29 juli 2026 om 19:02:28

Source:

nvd.nist.gov

Click to open the original link from this advisory

Network Infrastructure, Zero-Day Vulnerabilities

Xlight FTP Server versions before 3.9.5 contain a critical pre-authentication heap buffer overflow vulnerability tracked as CVE-2026-67191. The flaw allows remote unauthenticated attackers to write past the end of a heap buffer by sending a malformed SSH client identification string. The root cause is a logic error in the recv loop termination condition, where an incorrect OR operator is used instead of the required AND operator. This vulnerability is exploitable on any SSH or SFTP connection before authentication occurs, making it particularly dangerous as no credentials are needed. The attack surface is broad since it affects a fundamental protocol handshake step. The vulnerability has been patched in version 3.9.5 of the Xlight FTP Server. Both VulnCheck and the official Xlight changelog have published advisories regarding this issue. Given the pre-authentication nature and remote exploitability, this represents a high-severity risk to any exposed deployment.

Technical details

Mitigation steps:

Affected products:

Xlight FTP Server

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page