A recent report highlights three critical vulnerabilities in the Xlight FTP Server (CVE-2026-67191, CVE-2026-67192, and CVE-2026-67193) that allow for remote code execution and impact versions prior to 3.9.5. The most severe vulnerability, CVE-2026-67192, is a stack buffer overflow in the SSH GCM cipher handling, while CVE-2026-67191 is a heap buffer overflow. Both can allow memory corruption without authentication. The third issue (CVE-2026-67193) is a less severe information leak.
All flaws are rated with high CVSS scores, necessitating immediate updates to version 3.9.5, which addresses these vulnerabilities. There are currently no confirmed instances of exploitation.