14 entries matching openssh — updated 2026-09-18 · vulnfeed
| CVE / ID | Title | Severity | CVSS | EPSS | Source | Date |
|---|---|---|---|---|---|---|
| CVE-2026-69397 | Microsoft OpenSSH for Windows Remote Code Execution Vulnerability | HIGH | 7.5 | 46%ile | Microsoft | 2026-09-08 |
| CVE-2026-73282 | In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operat | MEDIUM | 4.8 | 6%ile | Microsoft | 2026-08-11 |
| CVE-2026-73281 | In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, includi | LOW | 3.5 | 5%ile | Microsoft | 2026-08-11 |
| CVE-2026-73283 | In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwar | LOW | 2.5 | 1%ile | Microsoft | 2026-08-11 |
| CVE-2026-60002 | ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This | HIGH | 7.7 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-60001 | sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay. | MEDIUM | 6.5 | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-59999 | In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not | MEDIUM | 5.9 | 6%ile | Microsoft | 2026-07-14 |
| CVE-2026-59998 | sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if th | MEDIUM | 4.8 | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-59995 | sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is u | MEDIUM | 4.2 | 17%ile | Microsoft | 2026-07-14 |
| CVE-2026-59996 | scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs betwee | MEDIUM | 4.2 | 17%ile | Microsoft | 2026-07-14 |
| CVE-2026-59997 | internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important | MEDIUM | 4.2 | 7%ile | Microsoft | 2026-07-14 |
| CVE-2026-60000 | sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive au | LOW | 3.7 | 38%ile | Microsoft | 2026-07-14 |
| CVE-2026-55655 | Openssh: local mitm of x11 forwarding via abstract unix socket pre-binding in red hat enterprise linux openssh client ve | MEDIUM | 5.0 | 0%ile | Microsoft | 2026-06-09 |
| CVE-2026-55653 | Openssh: double free in red hat enterprise linux versions of openssh dh-gex client path during fips known-group validati | MEDIUM | 4.3 | 22%ile | Microsoft | 2026-06-09 |