Skip to main content

Critical Remote Code Execution Vulnerability in libssh2

Successful exploitation could allow unauthenticated attackers to achieve remote code execution via crafted SSH packets

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Successful exploitation could allow unauthenticated attackers to achieve remote code execution via crafted SSH packets


Affected platforms

The following platforms are known to be affected:

Threat details

Introduction

The libssh2 project has released security updates to address a critical vulnerability in libssh2. Remote unauthenticated attackers could send crafted SSH packets with excessively large packet_length values to corrupt heap memory and achieve remote code execution (RCE).

  • CVE-2026-55200 - 'Integer Overflow to Buffer Overflow' vulnerability - CVSSv4 Base Score: 9.2

Remediation advice

Affected organisations are encouraged to review libssh2 advisory GHSA-R8MH-X5QV-7GG2 and apply the relevant update as soon as possible.


Definitive source of threat updates


Last edited: 23 June 2026 2:17 pm