FOUR new vulnerabilities in libssh2 threaten SSH and SFTP clients, allowing malicious servers to corrupt memory. Disclosed on July 24, 2026, these flaws carry a high severity rating of up to 8.8 on the CVSS scale. Key vulnerabilities include double-free heap corruption and integer underflow. While no exploitation has been confirmed, patches are available. Users are advised to update to specific commits to mitigate risks, and to connect only to trusted SSH servers until updated.
Serious libssh2 flaws let rogue SSH servers corrupt client memory
CyberSIXT Evidence Panel
Source marked as original reporting
Primary Source
github.com
Article by CyberSIXT
Timeline Coverage
Swipe to explore timeline
-
Serious libssh2 flaws let rogue SSH servers corrupt client memory
securityonline.info
-
Public PoC released for critical libssh2 SSH flaw CVE-2026-55200
thehackernews.com
-
CVE-2026-58050 bug lets bad SSH servers hijack libssh2 clients
securityonline.info
-
Libssh2 flaw CVE-2026-55200 allows remote code execution
securityonline.info