heise online A.I CyberSecurity Scoring
heise online
Company Information
Website:https://www.heise.de
Employees number:53
Number of followers:87,727
NAICS:511
Industry Type:Book and Periodical Publishing
Homepage:heise.de
heise online Risk Score (AI oriented)
Between 750 and 799
heise onlineBook and Periodical Publishing
Updated:
23/06/2026
23/06/2026
750/1000
Fair
Baa
heise online Global Score (TPRM)
xxxx
heise onlineBook and Periodical Publishing
Score locked

heise onlineFair
Current Score
750Baa (FAIR)
01000
1 incidents
-2 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
752
Vulnerability
23 Jun 2026 • heise online
libssh2: Critical libssh2 Vulnerability Lets Remote Attackers Execute Code via Crafted SSH Packets
Critical libssh2 Vulnerability (CVE-2026-55200) Enables Remote Code Execution
750
CRITICAL-2
HEI1782211360
Critical libssh2 Vulnerability (CVE-2026-55200) Enables Remote Code Execution
A severe security flaw in libssh2, a widely deployed client-side SSH library, has been disclosed, allowing remote attackers to execute arbitrary code via maliciously crafted SSH packets. The vulnerability, tracked as CVE-2026-55200, carries a CVSS score of 9.2, reflecting its high severity and ease of exploitation.
The issue stems from an integer overflow leading to a buffer overflow (CWE-680) in the `ssh2_transport_read()` function within `transport.c`. The flaw occurs due to insufficient validation of the `packet_length` field, enabling attackers to send oversized packets that trigger out-of-bounds memory writes. Successful exploitation results in heap corruption, allowing adversaries to overwrite adjacent memory and achieve arbitrary code execution all without requiring authentication.
The vulnerability affects libssh2 versions up to and including 1.11.1 and was patched in commit 7acf3df following responsible disclosure by security researcher Tristan Madani. The CVSS v4 vector highlights low attack complexity and no user interaction, making it particularly dangerous in automated systems, embedded devices, and backend infrastructures where libssh2 is integrated.
Given its broad adoption including in file transfer tools, automation frameworks, and custom SSH clients the flaw poses a significant risk, especially in enterprise environments where the library may be statically linked and difficult to detect. Organizations may unknowingly run vulnerable instances, even if their primary systems appear updated.
The maintainers have released a patch that enforces strict bounds checking on `packet_length` before memory allocation. Until updates are applied, mitigation measures include restricting SSH access to trusted hosts, network-level filtering, and monitoring for anomalous SSH traffic such as unusually large packets or application crashes tied to libssh2.
This incident underscores the persistent risks of memory safety vulnerabilities in widely used libraries and the critical need for robust input validation in network protocol implementations.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
MAY 2026
752
APRIL 2026
752
MARCH 2026
752
FEBRUARY 2026
752
JANUARY 2026
752
DECEMBER 2025
752
NOVEMBER 2025
752
OCTOBER 2025
752
SEPTEMBER 2025
752
AUGUST 2025
752
JULY 2025
752
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for heise online ??
What was heise online's A.I Rankiteo Cyber Score in May 2026 ??
What was heise online's A.I Rankiteo Cyber Score in April 2026 ??
What was heise online's A.I Rankiteo Cyber Score in March 2026 ??
What was heise online's A.I Rankiteo Cyber Score in February 2026 ??
What was heise online's A.I Rankiteo Cyber Score in January 2026 ??
What was heise online's A.I Rankiteo Cyber Score in December 2025 ??
What was heise online's A.I Rankiteo Cyber Score in November 2025 ??
What was heise online's A.I Rankiteo Cyber Score in October 2025 ??
What was heise online's A.I Rankiteo Cyber Score in September 2025 ??
What was heise online's A.I Rankiteo Cyber Score in August 2025 ??
What was heise online's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on heise online's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with heise online ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view heise online's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?