{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/proftpd-before-1.3.9c/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-63090"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["ProFTPD before 1.3.9c","ProFTPD before 1.3.10rc3"],"_cs_severities":["high"],"_cs_tags":["vulnerability","heap-overflow","rce","sftp"],"_cs_type":"advisory","_cs_vendors":["ProFTPD"],"content_html":"\u003cp\u003eProFTPD, an open-source FTP server, is affected by a critical heap-based buffer overflow vulnerability, CVE-2026-63090, residing within its \u003ccode\u003emod_sftp\u003c/code\u003e module. This flaw impacts versions prior to 1.3.9c and 1.3.10rc3. Authenticated low-privilege attackers can exploit this vulnerability by dispatching specially crafted SFTP packet fragments that exceed the 16 KB reassembly buffer in the \u003ccode\u003efxp.c\u003c/code\u003e component. Successful exploitation leads to memory corruption, allowing the attacker to manipulate critical pointers, specifically overwriting the \u003ccode\u003eroot_fs\u003c/code\u003e BSS global pointer. This manipulation redirects the \u003ccode\u003epr_fsio_stat()\u003c/code\u003e function to the \u003ccode\u003esystem()\u003c/code\u003e function, enabling arbitrary code execution through a crafted RENAME request. The vulnerability poses a significant risk to the integrity and confidentiality of systems running vulnerable ProFTPD installations.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn authenticated low-privilege attacker establishes an SFTP connection to a vulnerable ProFTPD server.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts and sends SFTP packet fragments that intentionally exceed the 16 KB reassembly buffer size in the \u003ccode\u003emod_sftp\u003c/code\u003e module's \u003ccode\u003efxp.c\u003c/code\u003e component.\u003c/li\u003e\n\u003cli\u003eThe oversized fragments trigger an incorrectly conditioned reallocation within the server's memory management.\u003c/li\u003e\n\u003cli\u003eThis leads to a heap-based buffer overflow, corrupting pool freelist metadata in memory.\u003c/li\u003e\n\u003cli\u003eThe attacker then manipulates the corrupted memory to overwrite the \u003ccode\u003eroot_fs\u003c/code\u003e BSS global pointer, redirecting it to reference a fake filesystem structure.\u003c/li\u003e\n\u003cli\u003eThis pointer redirection causes subsequent calls to the \u003ccode\u003epr_fsio_stat()\u003c/code\u003e function to instead execute the \u003ccode\u003esystem()\u003c/code\u003e function.\u003c/li\u003e\n\u003cli\u003eThe attacker sends a crafted RENAME request, which now serves as a vehicle to pass arbitrary commands to the \u003ccode\u003esystem()\u003c/code\u003e function.\u003c/li\u003e\n\u003cli\u003eArbitrary code execution is achieved on the underlying server with the privileges of the ProFTPD process.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-63090 grants an authenticated low-privilege attacker arbitrary code execution capabilities on the affected server. This allows the attacker to execute any commands with the privileges of the ProFTPD process, potentially leading to full system compromise, data exfiltration, service disruption, or further lateral movement within the network. While no specific victim counts or targeted sectors are mentioned, any organization utilizing vulnerable ProFTPD installations is at risk of severe security breaches, impacting data confidentiality, integrity, and availability.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-63090 on all ProFTPD installations by upgrading to versions 1.3.9c, 1.3.10rc3, or later immediately.\u003c/li\u003e\n\u003cli\u003eEnable comprehensive logging for ProFTPD servers, specifically focusing on SFTP command logs and system call attempts, to identify unusual activity that could indicate exploitation of CVE-2026-63090.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-20T15:19:56Z","date_published":"2026-07-20T15:19:56Z","id":"https://feed.craftedsignal.io/briefs/2026-07-profotpd-mod-sftp-rce/","summary":"A heap-based buffer overflow vulnerability exists in the mod_sftp module of ProFTPD versions prior to 1.3.9c and 1.3.10rc3, allowing authenticated low-privilege attackers to achieve arbitrary code execution by sending specially crafted SFTP packet fragments exceeding 16 KB, corrupting memory and redirecting function calls.","title":"ProFTPD mod_sftp Heap Buffer Overflow Leads to Arbitrary Code Execution","url":"https://feed.craftedsignal.io/briefs/2026-07-profotpd-mod-sftp-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - ProFTPD Before 1.3.9c","version":"https://jsonfeed.org/version/1.1"}