A vulnerability, which was classified as very critical, has been found in ProFTPD up to 1.3.9b/1.3.10rc2. This affects an unknown function of the component Mod Sftp. Performing a manipulation results in integer overflow.
This vulnerability is cataloged as CVE-2026-63091. It is possible to initiate the attack remotely. There is no exploit available.