ProFTPD vulnerability can give attackers control of FTP servers

ProFTPD has released a security update for CVE-2026-42167, a high-severity vulnerability affecting versions up to and including 1.3.9. The flaw could allow attackers to bypass authentication and run code on exposed FTP servers. Systems using the optional mod_sql extension are particularly at risk. There are no confirmed reports of exploitation, but public proof-of-concept code is available. Updating to ProFTPD 1.3.9a is recommended.

What this means for your organisation

FTP servers are often what gets left behind: set up long ago to exchange files with a customer or supplier, then forgotten by everyone who does not use them daily. That is precisely why they rarely make it into the patch cycle. An exposed ProFTPD with public exploit code is a realistic entry point into the network, and the files sitting on it are usually not worthless.

Berigo recommends

  • Update to ProFTPD 1.3.9a on every server reachable from the internet.
  • Disable mod_sql logging features where patching cannot be done straight away.
  • Consider whether the FTP service is still needed, or whether the file exchange can move to a solution that is actively maintained.
  • Scan your own address space from the outside to find services nobody remembers leaving in place.

Source

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch