logo

Critical libssh2 Vulnerability CVE-2026-55200 Enables Remote Code Execution

ID: f8c30132-0001-5727-baff-411857e91de1

STIX ID: report--f8c30132-0001-5727-baff-411857e91de1

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-06-23

Date Updated: 2026-06-23

Author: Do Son

...
...

### Executive summary A critical libssh2 vulnerability (CVE-2026-55200, CVSS 9.2) allows unauthenticated remote attackers to trigger an out-of-bounds write during SSH packet processing by abusing an unchecked packet_length in ssh2_transport_read(), potentially enabling remote code execution; the issue affects releases up to 1.11.1, a patch commit has been published, and no in-the-wild exploitation has been confirmed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.