Home / Jun 30, 2026 / Story
0
#6 The Hacker News general June 29, 2026 at 07:06 UTC

Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw

By [email protected] (The Hacker News)

AI Summary

A public proof-of-concept has been released for CVE-2026-55200, a CVSS 4.0 score 9.2 memory corruption flaw in libssh2 affecting all versions up to and including 1.11.1. The vulnerability is client-side — a malicious or compromised SSH server can trigger arbitrary code execution on connecting clients with no credentials or user interaction required. Given libssh2's widespread use as an embedded SSH library, defenders should prioritize patching any systems or applications linking against versions ≤1.11.1.

Relevance score: 83.0/100

# More from June 30