References https://nvd.nist.gov/vuln/detail/CVE-2023-53886 https://www.vulncheck.com/advisories/xlight-ftp-server-stack-buffer-overflow-vulnerability-via-execute-program https://www.exploit-db.com/exploits/51665 https://access.redhat.com/security/cve/cve-2023-53886 https://www.tenable.com/cve/CVE-2023-53886 https://github.com/advisories/GHSA-hxpr-5v98-mw59 https://www.xlightftpd.com/ https://vulnerability.circl.lu/search?vendor=Xlightftpd&product=Xlight+FTP+Server
Related VulnerabilitiesPoCCVE-2026-6639: AI Copilot Content Generator <=1.4.6 - Unauthenticated Task Data ExposurePoCpowerdns-monitor-exposure: PowerDNS Authoritative Server Monitor - Unauthenticated ExposurePoCCVE-2021-42392: H2 Database Console - JNDI Injection RCEPoCCVE-2026-13153: Essential Blocks < 6.4.0 - Information DisclosurePoCCVE-2026-1340: Ivanti EPMM < 12.8.0.0 - Remote Code ExecutionPoCCVE-2026-69085: SiYuan <=3.7.2 - SQL InjectionPoCCVE-2026-84434: WordPress Gravity Forms Plugin <=3.1.0.4 - Unauthenticated Arbitrary File UploadPoCCVE-2026-86218: N-able N-central <2026.3.1.14 - Pre-Authentication Remote Code ExecutionPoCCVE-2026-9103: Langflow OSS - Superuser Token IssuancePoChttp-etcd-unauthenticated-api-v3: etcd v3 Unauthenticated APICuteHttpFileServer/chfs存在未授权任意文件上传PoCCVE-2026-27960: OpenCTI < 6.9.13 - Authentication Bypass via User ImpersonationPoCCVE-2020-29134: TOTVS Fluig <= 1.7.0 - Arbitrary File Read