chiprook
← Security
SecuritySeptember 16, 2026, 14:21

CVE-2026-42167: ProFTPD mod_sql RCE and How to Analyze the Exploit-DB PoC

A public PoC for CVE-2026-42167 in the mod_sql extension of the ProFTPD server, with a CVSS score of 8.1, has been published on Exploit-DB. The exploit demonstrates a path from SQL injection to RCE after authentication when using PostgreSQL; the fix is ProFTPD 1.3.9a.

CVE-2026-42167: ProFTPD mod_sql RCE and How to Analyze the Exploit-DB PoC
#ProFTPD
Read next
Security

Contagious Interview Campaign Hits 30,000 Devices, Steals $10.71M in Crypto

Security

Google Releases AndroidX Libraries for Granular Android Patch Checks

Security

Surfshark: iPhone lets you delete 98% of preinstalled apps, Google only 38%

Security

Hackers extract 1.6 million images and 27,000 videos from a single Flock camera