<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T20:35:53.466686+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:69129</id>
    <title>ALSA-2026:69129 — Important: openssh security update</title>
    <updated>2026-10-02T20:35:53.850641+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: openssh, AlmaLinux:10: openssh-askpass, AlmaLinux:10: openssh-clients, AlmaLinux:10: openssh-keycat, AlmaLinux:10: openssh-keysign, AlmaLinux:10: openssh-server</p>
<p>OpenSSH is an SSH protocol implementation supported by a number of Linux, UNIX, and similar operating systems. It includes the core files necessary for both the OpenSSH client and server.</p>
<p>Security Fix(es):</p>
<p>* openssh: OpenSSH: sftp client allows attacker to control downloaded file location (CVE-2026-59995)
  * openssh: OpenSSH sshd: Security bypass due to incorrect handling of forwarding and tunneling options (CVE-2026-59999)
  * openssh: OpenSSH: Tunnel forwarding restriction bypass (CVE-2026-73283)
  * openssh: OpenSSH: ssh-agent allows remote execution of local operations (CVE-2026-73281)
  * openssh: OpenSSH: Information disclosure and data corruption via use-after-free in ssh client (CVE-2026-73282)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:69129"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-59999</id>
    <title>BELL-CVE-2026-59999</title>
    <updated>2026-10-02T20:35:53.850715+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: openssh, Alpaquita:25: openssh, Alpaquita:stream: openssh, BellSoft Hardened Containers:23: openssh, BellSoft Hardened Containers:25: openssh, BellSoft Hardened Containers:stream: openssh</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-59999"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0873</id>
    <title>certfr-2026-avi-0873 — De multiples vulnérabilités ont été découvertes dans Microsoft Azure Linux. Elles permettent à un attaquant de provoque…</title>
    <updated>2026-10-02T20:35:53.850746+00:00</updated>
    <content>certfr-2026-avi-0873</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0873"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-333871</id>
    <title>EUVD-2026-333871</title>
    <updated>2026-10-02T20:35:53.850764+00:00</updated>
    <content>EUVD-2026-333871</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-333871"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-59999</id>
    <title>fkie_cve-2026-59999</title>
    <updated>2026-10-02T20:35:53.850776+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-59999"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-gcm2-x6hm-q4h3</id>
    <title>GHSA-gcm2-x6hm-q4h3</title>
    <updated>2026-10-02T20:35:53.850797+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-gcm2-x6hm-q4h3"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-59999</id>
    <title>msrc_CVE-2026-59999 — In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did no…</title>
    <updated>2026-10-02T20:35:53.850810+00:00</updated>
    <content>msrc_CVE-2026-59999</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-59999"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ncsc-2026-0321</id>
    <title>NCSC-2026-0321 — Meerdere kwetsbaarheden verholpen in IBM AIX en IBM PowerVM VIOS</title>
    <updated>2026-10-02T20:35:53.850826+00:00</updated>
    <content>NCSC-2026-0321</content>
    <link href="https://cve.radiocsirt.org/vuln/ncsc-2026-0321"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-3349</id>
    <title>OESA-2026-3349 — openssh security update</title>
    <updated>2026-10-02T20:35:53.851028+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP4: openssh</p>
<p>An open source implementation of SSH protocol version 2

Security Fix(es):</p>
<p>sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when &amp;quot;sftp server:/path .&amp;quot; is used with an attacker-controlled server.(CVE-2026-59995)</p>
<p>internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection.(CVE-2026-59997)</p>
<p>In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.(CVE-2026-59999)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-3349"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21477-1</id>
    <title>openSUSE-SU-2026:21477-1 — Security update for openssh</title>
    <updated>2026-10-02T20:35:53.851055+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for openssh</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:21477-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:37382</id>
    <title>RHSA-2026:37382 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
    <updated>2026-10-02T20:35:53.851076+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>openssh: OpenSSH: sftp client allows attacker to control downloaded file location openssh: OpenSSH: `scp` file misplacement vulnerability during remote copy openssh: OpenSSH: SFTP security bypass due to command-line argument parsing flaw openssh: OpenSSH: Undocumented GSSAPIStrictAcceptorCheck behavior impacts security in Windows Active Directory openssh: OpenSSH sshd: Security bypass due to incorrect handling of forwarding and tunneling options openssh: OpenSSH: Denial of Service via excessive GSSAPI authentication attempts openssh: OpenSSH: Brute-force attacks facilitated due to insufficient authentication delay openssh: OpenSSH: Use-after-free vulnerability during host key re-exchange on the client side</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:37382"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:69129</id>
    <title>RLSA-2026:69129 — Important: openssh security update</title>
    <updated>2026-10-02T20:35:53.851104+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: openssh</p>
<p>OpenSSH is an SSH protocol implementation supported by a number of Linux, UNIX, and similar operating systems. It includes the core files necessary for both the OpenSSH client and server.</p>
<p>Security Fix(es):</p>
<p>* openssh: OpenSSH: sftp client allows attacker to control downloaded file location (CVE-2026-59995)</p>
<p>* openssh: OpenSSH sshd: Security bypass due to incorrect handling of forwarding and tunneling options (CVE-2026-59999)</p>
<p>* openssh: OpenSSH: Tunnel forwarding restriction bypass (CVE-2026-73283)</p>
<p>* openssh: OpenSSH: ssh-agent allows remote execution of local operations (CVE-2026-73281)</p>
<p>* openssh: OpenSSH: Information disclosure and data corruption via use-after-free in ssh client (CVE-2026-73282)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:69129"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:22978-1</id>
    <title>SUSE-SU-2026:22978-1 — Security update for openssh</title>
    <updated>2026-10-02T20:35:53.851131+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for openssh</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:22978-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-59999</id>
    <title>UBUNTU-CVE-2026-59999</title>
    <updated>2026-10-02T20:35:53.851150+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:FIPS:16.04:LTS: openssh, Ubuntu:Pro:18.04:LTS: openssh, Ubuntu:18.04:LTS: openssh-ssh1, Ubuntu:Pro:FIPS-updates:18.04:LTS: openssh, Ubuntu:Pro:FIPS:18.04:LTS: openssh, Ubuntu:Pro:20.04:LTS: openssh, Ubuntu:20.04:LTS: openssh-ssh1, Ubuntu:Pro:FIPS-updates:20.04:LTS: openssh, Ubuntu:Pro:FIPS:20.04:LTS: openssh, Ubuntu:22.04:LTS: openssh and 10 more</p>
<p>In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-59999"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2221</id>
    <title>WID-SEC-W-2026-2221 — OpenSSH: Mehrere Schwachstellen</title>
    <updated>2026-10-02T20:35:53.851195+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in OpenSSH ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, und um Sicherheitsvorkehrungen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2221"/>
  </entry>
</feed>
