Skip to content

Xlight vulnerabilities

3 CVEs tracked

Xlight FTP Server appears in our reporting with critical security vulnerabilities. The provided summaries highlight three pre-authentication flaws (CVE-2026-67191 heap buffer overflow, CVE-2026-67192 stack buffer overflow, CVE-2026-67193 information disclosure) affecting versions prior to 3.9.5, all exploitable remotely. Defenders should immediately upgrade to version 3.9.5 and monitor network traffic for suspicious SSH identification strings and FTP USER commands targeting these pre-auth vectors.

Azərbaycanca: Xlight FTP Server hesabatlarımızda kritik təhlükəsizlik zəiflikləri ilə bağlı görünür. Təqdim olunan xülasələr 3.9.5 versiyasından əvvəlki məhsula təsir edən, autentifikasiya öncəsi istismar edilə bilən üç ciddi zəifliyi (CVE-2026-67191 heap buffer overflow, CVE-2026-67192 stack buffer overflow, CVE-2026-67193 məlumat sızması) vurğulayır. Müdafiəçilər dərhal 3.9.5 versiyasına yüksəltməli və şəbəkə səviyyəsində xüsusilə SSH identifikasiyası və FTP USER əmrlərinə daxil olan şübhəli trafikə nəzarət etməlidir.

This vendor's CVEs3

This hub is built from skopnix's own reporting on Xlight: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.