It was discovered that libssh2 incorrectly handled certain SFTP server responses. A remote attacker controlling an SSH server could use this issue to cause libssh2 to crash or possibly execute arbitrary code. (CVE-2026-66032) It was discovered that libssh2 incorrectly handled AES-GCM cipher negotiation.
USN-8722-1: libssh2 vulnerabilities
calendar_today
September 3, 2026
domain
ubuntu