# CVE-2026-53994 — ProFTPD

> As of 2026-07-18, CVE-2026-53994 is a HIGH-severity vulnerability in ProFTPD, CVSS v3.1 7.5, EPSS 0.4% (32.8th percentile). No Threadlinqs-tracked threat campaign has been attributed to CVE-2026-53994 as of 2026-07-18; the identifier is re-checked against the Threadlinqs threat corpus on every daily ingest.

**Last updated:** 2026-07-18

## What is CVE-2026-53994?

ProFTPD mod_sftp contains a heap-based buffer overflow reachable by an authenticated SFTP user. The fxp_packet_read() function accepts the attacker-supplied 32-bit big-endian SFTP packet length without a minimum sanity check. A value of 0 causes an unsigned subtraction elsewhere in the read path to underflow to approximately 4 GB. That oversized request reaches the core memory allocator, where the rounded size is computed in size_t but passed to new_block() as a 32-bit int; the low 32 bits of 0x100000000 are 0, so new_block() returns a small (~512-byte) block while the caller is told it received ~4 GB. The subsequent fill loop then streams attacker-controlled bytes past the end of the 544-byte allocation, producing an attacker-controlled heap buffer overflow. An authenticated user can crash the per-connection ProFTPD session child on demand with a single malformed SFTP packet (packet_len=0 followed by a body greater than approximately 544 bytes), producing reliable authenticated remote denial of service. Depending on heap layout and adjacent allocations, heap metadata corruption and further consequences beyond denial of service may be possible, though only denial of service is demonstrated by the supplied proof of concept.

The record classifies CVE-2026-53994 under weakness class [CWE-122](https://intel.threadlinqs.com/cwe/CWE-122). Its CVSS v3 base vector states that the flaw is reachable remotely over the network, needs low-privilege credentials, needs no user interaction, and has high impact on confidentiality, integrity, availability. 1 affected-product entry is recorded, across 1 vendor, listed below. The identifier was first published 79 days ago.

## Severity and exploitation probability

- **CVSS v3.1 base score:** 7.5 — HIGH (`CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H`)
- **CVSS v4.0 base score:** 7.7 (`CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N`)
- **EPSS (FIRST):** 0.4% probability of exploitation in the next 30 days, higher than 32.8% of all scored CVEs
- **CISA KEV:** Not listed in the CISA Known Exploited Vulnerabilities catalog
- **Threadlinqs priority:** 7.1/10 — a Threadlinqs composite of the CVSS base score, the EPSS percentile and public exploit availability
- **Published:** 2026-07-18

## Is CVE-2026-53994 being exploited?

Weaponised exploit code for CVE-2026-53994 is publicly available. 1 public proof-of-concept repository is tracked for this identifier. It currently carries a trending score of 46 in the Threadlinqs vulnerability feed.

- [trickest/cve](https://github.com/trickest/cve/blob/main/2026/CVE-2026-53994.md) (trickest)

## Affected products and versions

- **ProFTPD Project**: ProFTPD

## How to fix CVE-2026-53994

No vendor patch reference has been recorded for CVE-2026-53994 in the tracked sources. Follow the references below for a fix, and treat the products listed above as exposed until the vendor states otherwise.

## Threat activity tracking CVE-2026-53994

No threat campaign in the Threadlinqs corpus currently references CVE-2026-53994, in its CVE list or as an indicator. The linkage is recomputed from the live corpus on every daily ingest, so this section fills in as soon as a tracked campaign cites the identifier.

## Sources

Enriched from CVE.org, NVD, FIRST EPSS, GitHub Security Advisories, public proof-of-concept repositories. Last verified by Threadlinqs on 2026-07-20. This product uses the NVD API but is not endorsed or certified by the NVD.

**Vendor advisory and patch**

- [github.com — patch](https://github.com/proftpd/proftpd/commit/7342836fa98e36209660a4c5805c801476f63936)

**Third-party advisory**

- [vulncheck.com — third party advisory](https://www.vulncheck.com/advisories/proftpd-mod-sftp-heap-buffer-overflow-via-unsigned-integer-underflow-and-size-truncation)

**Issue tracking and product pages**

- [github.com — product](https://github.com/proftpd/proftpd)

Canonical: https://intel.threadlinqs.com/cve/CVE-2026-53994
Full detection coverage and IOCs for threats exploiting CVE-2026-53994 via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
