logo

Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw

ID: df0cfc59-b03c-56a3-99d8-60adcacfced4

STIX ID: report--df0cfc59-b03c-56a3-99d8-60adcacfced4

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2026-06-29

Date Updated: 2026-07-01

Author: [email protected] (The Hacker News)

...
...

A critical libssh2 vulnerability (CVE-2026-55200, CVSS 9.2) enables a malicious SSH server to craft an oversized packet_length that causes an integer overflow and heap buffer overflow in clients (libssh2 ≤ 1.11.1), potentially allowing code execution; a public proof-of-concept exists but no confirmed in-the-wild exploitation yet, and patches/backports are being applied—organizations should inventory bundled/static copies of libssh2, apply the patch (commit 97acf3d) or vendor updates, and restrict outbound SSH until mitigated.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.