CVE-2026-42167: ProFTPD

High severity, CVSS 8.1. EPSS: 7.3% chance of exploitation in the next 30 days.

mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of USER requests with an expansion such as %U, and the SQL backend allows commands (e.g., COPY TO PROGRAM).

Affected products

  • ProFTPD ProFTPD: up to and including 1.3.9b

Published 2026-04-28. Last modified 2026-07-24.