{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aproftpdproftpd/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:proftpd:proftpd:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-42167"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["ProFTPD"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["ProFTPD"],"content_html":"\u003cp\u003eCVE-2026-42167 is a critical vulnerability affecting the ProFTPD server, specifically within the mod_sql module. This vulnerability allows an authenticated user to perform SQL injection attacks, which can be further weaponized to achieve remote code execution on the underlying host. The vulnerability was disclosed alongside a functional exploit (EDB-52658), significantly increasing the risk to environments where ProFTPD is deployed with SQL-based authentication or logging enabled. Defenders should prioritize patching or disabling the mod_sql module if it is not strictly required, as the public availability of the exploit simplifies the path to system compromise for attackers who have obtained valid FTP credentials.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for arbitrary code execution with the privileges of the ProFTPD service. This can lead to full system compromise, data exfiltration, and lateral movement within the network. The scope of impact is limited to servers running ProFTPD with the mod_sql module enabled.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eApply vendor patches for CVE-2026-42167 across all affected ProFTPD instances immediately.\u003c/li\u003e\n\u003cli\u003eDisable the mod_sql module in the ProFTPD configuration file if it is not necessary for business operations.\u003c/li\u003e\n\u003cli\u003eMonitor authentication logs for suspicious patterns originating from authenticated FTP users, specifically those interacting with database-backed authentication components.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-25T16:37:15Z","date_published":"2026-08-25T16:37:15Z","id":"https://feed.craftedsignal.io/briefs/2026-08-proftpd-sqli/","summary":"An authenticated SQL injection vulnerability (CVE-2026-42167) in the ProFTPD mod_sql module allows attackers to achieve remote code execution, with a functional exploit now publicly available.","title":"CVE-2026-42167: Remote Code Execution via ProFTPD mod_sql","url":"https://feed.craftedsignal.io/briefs/2026-08-proftpd-sqli/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:proftpd:proftpd:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}