June 29, 2026
- CVE-2026-55200 in libssh2 now has a public PoC. The critical flaw (CVSS 4.0 score 9.2) lets a malicious or compromised SSH server trigger memory corruption — and possibly code execution — on a connecting client with no credentials or interaction. It affects all releases up to and including 1.11.1; note this is a client-side library, so the exposure is anything that dials out over SSH using libssh2. (The Hacker News) · Vulnerabilities & Exploits
in Public Root Exploit for Linux "pedit COW" Lands as Offensive Tooling Floods the Week