CVE-2026-28295Disclosure

LOWCVSS 4.3 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in the FTP GVfs backend. A malicious FTP server can exploit this vulnerability by providing an arbitrary IP address and port in its passive mode (PASV) response. The client unconditionally trusts this information and attempts to connect to the specified endpoint, allowing the malicious server to probe for open ports accessible from the client's network.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-02-26); latest day: 2
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-02-26: 2Mentions · 2026-03-23: 2Patch / Workaround · 2026-03-23: 2Technical Details · 2026-02-26: 2Technical Details · 2026-03-23: 202-2603-23
Signal classification3 categories
Disclosure
250.0%
General
125.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-262
Disclosure1General1
2026-03-232
Disclosure1Patch1
Full discourse4 posts
  • Ferramentas Linux@Cezar_H_Linux
    Disclosure

    ⚠️ URGENT: Canonical issues USN-8114-1 for @Ubuntu 22.04-25.10. Critical GVfs RCE vulns (CVE-2026-28295, CVE-2026-28296) in FTP backend. Read more: 👉 https://tinyurl.com/mupeehtp #Security https://t.co/eXul5oKyOz

    Post summary

    Canonical has issued an urgent security advisory (USN-8114-1) for Ubuntu 22.04-25.10, highlighting two critical GVfs remote code execution vulnerabilities affecting the FTP backend, and provides a link for further details.

    0002076
    1.5K followersView on X
  • ThreatCluster@threatcluster
    Patch

    Ubuntu security update fixes GVfs FTP RCE flaws CVE-2026-28295/28296 in 25.10, 24.04 LTS, 22.04 LTS. Remote servers could scan ports or inject code. Update and restart. #Linux https://threatcluster.io/cluster/critical-gvfs-vulnerabilities-in-ubuntu-allow-remote-code-ex-1e94a86e

    Post summary

    The post announces Ubuntu security updates for GVfs FTP RCE flaws (CVE-2026-28295/28296) and advises users to install the patch and restart to mitigate the vulnerabilities.

    0000042
    112 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-28295 A flaw was found in the FTP GVfs backend. A malicious FTP server can exploit this vulnerability by providing an arbitrary IP address and port in its passive mode (PAS… https://www.cve.org/CVERecord?id=CVE-2026-28295

    Post summary

    A vulnerability in the FTP GVfs backend allows a malicious FTP server to specify arbitrary IP addresses and ports in passive mode, potentially enabling exploitation.

    00000111
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-28295 FTP GVfs Backend Vulnerability Enables Arbitrary Network Port Probing https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28295

    Post summary

    The post references CVE-2026-28295, noting it allows arbitrary network port probing via the FTP GVfs backend, but provides no further details, PoC, or patch information.

    0000034
    4.0K followersView on X

Explore more