Critical libssh2 Vulnerabilities Allow Remote Code Execution and DoS

Critical libssh2 Vulnerabilities Allow Remote Code Execution and DoS

First seen 3 Sep 2026, 17:39 UTC UbuntuLinuxsecuritylaunchpad.net 60.6

Article Content

Browse articles
ThreatCluster

Multiple vulnerabilities were discovered in libssh2, affecting its handling of SFTP server responses and cipher negotiations. These flaws could allow remote attackers controlling an SSH server to crash libssh2 or execute arbitrary code. The vulnerabilities are identified as CVE-2026-66032, CVE-2026-66033, and CVE-2026-66035, all published on 2026-07-24. Affected systems include Ubuntu 26.04 and 24.04 LTS. Users are advised to update their systems to mitigate these security risks. A standard system update is recommended to apply the necessary patches. The vulnerabilities pose a significant risk of denial of service and potential remote code execution.

Key Points: • libssh2 vulnerabilities could lead to remote code execution and DoS. • Affected CVEs include CVE-2026-66032, CVE-2026-66033, and CVE-2026-66035. • Users should update to the latest package versions to mitigate risks.

Timeline

2026-07-24
CVE-2026-66032 published
libssh2 incorrectly handled certain SFTP server responses, allowing potential remote code execution.
Ubuntu
2026-07-24
CVE-2026-66033 published
libssh2 mishandled AES-GCM cipher negotiation, leading to possible denial of service.
Ubuntu
2026-07-24
CVE-2026-66035 published
libssh2 failed to correctly handle Encrypt-then-MAC cipher negotiation, risking remote code execution.
Ubuntu
2026-09-03
Security notice issued
Ubuntu published a security notice urging users to update their systems to mitigate the vulnerabilities.
Linuxsecurity