Critical Alert 1 Active Exploit Detected Today

CVE-2026-18577 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability →
Powered by CVE Watchtower
×
August 4, 2026

CVE Watchtower


← Back to CVE List

CVE-2026-67193NVD

Vulnerability Summary

Xlight FTP Server before 3.9.5 contains an information disclosure vulnerability that allows unauthenticated attackers to obtain the server's current GetTickCount() value by sending a USER command with a username ending in the :adm suffix. Attackers can trigger the admin protocol path within the standard FTP listener pre-authentication to leak timing information from the FTP 331 response without requiring a separate port or configuration change.
Severity Level
MEDIUM(5.3)
Published Date
Jul 29, 2026
Last Modified
Jul 29, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
0.26%Probability
Root Weakness (CWE)
N/A
CVSS v3.1 Base Metrics
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityLow
IntegrityNone
AvailabilityNone