CPE
An authenticated SQL injection vulnerability (CVE-2026-42167) in the ProFTPD mod_sql module allows attackers to achieve remote code execution, with a functional exploit now publicly available.