CVE-2026-42167: ProFTPD
High severity, CVSS 8.1. EPSS: 7.3% chance of exploitation in the next 30 days.
mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of USER requests with an expansion such as %U, and the SQL backend allows commands (e.g., COPY TO PROGRAM).
Affected products
- ProFTPD ProFTPD: up to and including 1.3.9b
Published 2026-04-28. Last modified 2026-07-24.