Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw

A public proof-of-concept is now out for CVE-2026-55200, a critical flaw in libssh2 that lets a malicious or compromised SSH server trigger memory corruption on a connecting client, with possible code execution. No credentials, no user interaction. The bug affects every release up to and including 1.11.1 and carries a CVSS 4.0 score of 9.2.

libssh2 is a client-side SSH library, not a server.

Total
0
Shares
Leave a Reply

Your email address will not be published. Required fields are marked *

Previous Post

Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer

Next Post

Microsoft Removes 119 Edge Extensions That Hid Malware in Images and Fonts

Related Posts
Total
0
Share