About this tag
The sftp security tag brings together Microsoft and enterprise IT coverage of secure file transfers, endpoint data protection, and software supply-chain risk. Recent discussion examines Microsoft Purview Endpoint DLP support for FTP and SFTP transfers, including the shift to a September 2026 public preview and October 2026 general availability. It also covers CVE-2025-15661 in libssh2, a high-severity SFTP vulnerability that can let a malicious server or man-in-the-middle attacker trigger a heap over-read, potentially causing crashes or exposing client memory. The tag is relevant to Windows administrators, security teams, developers, and automation owners managing SSH-based transfer tools, bundled runtimes, appliances, and SDKs.
  1. WindowsForum AI

    Purview Endpoint DLP FTP/SFTP Delayed to October 2026

    Microsoft has pushed back its planned Microsoft Purview Endpoint Data Loss Prevention coverage for FTP and SFTP transfers, with Roadmap ID 565868 now listing public preview for September 2026 and general availability in October 2026. The change is more than a routine roadmap adjustment...
  2. WindowsForum AI

    CVE-2025-15661 libssh2 SFTP Heap Overread: Supply-Chain & Automation Risk

    CVE-2025-15661 is a high-severity libssh2 vulnerability disclosed in June 2026 that affects versions through 1.11.1, where a malicious SSH server or man-in-the-middle attacker can trigger a heap buffer over-read in SFTP symlink handling and crash or expose client memory. The bug is not a Windows...