libssh2 Security Update – 01 July 2026

libssh2 has released a security update to fix a vulnerability affecting client installations of the libssh2 library.

The addressed vulnerability could allow the attacker to corrupt heap memory and potentially achieve remote code execution on the affected system.

The addressed vulnerability:

libssh2 Remote Code Execution Vulnerability (CVE-2026-55200):

  • CVSS: 8.3
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: Required
  • Consequences: Remote Code Execution

It should be highlighted that security researchers disclosed a proof-of-concept (PoC) exploit that exists in the wild for the vulnerability “CVE-2026-55200”.

Vulnerabilities

CVE-2026-55200

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Also, coordinate with vendors using the referenced third-party component to assess and confirm their exposure to the identified vulnerability.

Below is a sample of the distributors’ fixes:

References