Post
CRITICAL

Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw

· cve · vulnerability · rce

A public proof-of-concept exploit has been released for CVE-2026-55200, a critical memory corruption flaw in libssh2, a widely used client-side SSH library. The bug lets a malicious or compromised SSH server trigger memory corruption on a connecting client with no credentials or user interaction required, potentially leading to code execution. It carries a CVSS 4.0 score of 9.2 and affects all releases up to and including 1.11.1. Anyone embedding libssh2 in client applications should patch or pin to a fixed version once available and review SSH server trust assumptions.