A vulnerability classified as very critical has been found in ProFTPD up to 1.3.9b/1.3.10rc2. The affected element is the function pr_fsio_stat of the file fxp.c of the component Mod Sftp. This manipulation causes heap-based buffer overflow.

This vulnerability is tracked as CVE-2026-63090. The attack is possible to be carried out remotely. No exploit exists.