Skip to main content
HIGH

CVE-2026-53994

CVSS v3

7.5

HIGH

EPSS Score

0.7 %

exploit probability, as of 2026-10-06

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

ProFTPD mod_sftp contains a heap-based buffer overflow reachable by an authenticated SFTP user. The fxp_packet_read() function accepts the attacker-supplied 32-bit big-endian SFTP packet length without a minimum sanity check. A value of 0 causes an unsigned subtraction elsewhere in the read path to underflow to approximately 4 GB. That oversized request reaches the core memory allocator, where the rounded size is computed in size_t but passed to new_block() as a 32-bit int; the low 32 bits of 0x

Technical details

Published
2026-07-18
Last Modified
2026-07-18

Frequently asked questions

What is CVE-2026-53994?

ProFTPD mod_sftp contains a heap-based buffer overflow reachable by an authenticated SFTP user. The fxp_packet_read() function accepts the attacker-supplied 32-bit big-endian SFTP packet length without a minimum sanity check. A value of 0 causes an unsigned subtraction elsewhere in the read path to underflow to approximately 4 GB. That oversized request reaches the core memory allocator, where the rounded size is computed in size_t but passed to new_block() as a 32-bit int; the low 32 bits of 0x

Is CVE-2026-53994 actively exploited?

Active exploitation of CVE-2026-53994 has not been confirmed. Its EPSS score was 0.7% on 2026-10-06, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2026-53994?

CVE-2026-53994 has a CVSS v3 base score of 7.5 (HIGH severity).

Is CVE-2026-53994 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 50 free checks/month · Free API key