<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T15:28:02.518391+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:47756</id>
    <title>ALSA-2026:47756 — Important: openssh security update</title>
    <updated>2026-10-02T15:28:02.936997+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: openssh, AlmaLinux:9: openssh-askpass, AlmaLinux:9: openssh-clients, AlmaLinux:9: openssh-keycat, AlmaLinux:9: openssh-server, AlmaLinux:9: pam_ssh_agent_auth</p>
<p>OpenSSH is an SSH protocol implementation supported by a number of Linux, UNIX, and similar operating systems. It includes the core files necessary for both the OpenSSH client and server.</p>
<p>Security Fix(es):</p>
<p>* openssh: Local MITM of X11 forwarding via abstract UNIX socket pre-binding in AlmaLinux OpenSSH client versions (CVE-2026-55655)
  * openssh: Double free in AlmaLinux versions of OpenSSH DH-GEX client path during FIPS known-group validation leads to client-side denial of service (CVE-2026-55653)
  * openssh: Heap out-of-bounds read in AlmaLinux versions of OpenSSH GSSAPI indicator cleanup due to missing NULL sentinel termination (CVE-2026-55654)
  * openssh: OpenSSH: Use-after-free vulnerability during host key re-exchange on the client side (CVE-2026-60002)
  * openssh: OpenSSH: `scp` file misplacement vulnerability during remote copy (CVE-2026-59996)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:47756"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-60002</id>
    <title>BELL-CVE-2026-60002</title>
    <updated>2026-10-02T15:28:02.937095+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: openssh, Alpaquita:25: openssh, Alpaquita:stream: openssh, BellSoft Hardened Containers:23: openssh, BellSoft Hardened Containers:25: openssh, BellSoft Hardened Containers:stream: openssh</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-60002"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0873</id>
    <title>certfr-2026-avi-0873 — De multiples vulnérabilités ont été découvertes dans Microsoft Azure Linux. Elles permettent à un attaquant de provoque…</title>
    <updated>2026-10-02T15:28:02.937126+00:00</updated>
    <content>certfr-2026-avi-0873</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0873"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-333858</id>
    <title>EUVD-2026-333858</title>
    <updated>2026-10-02T15:28:02.937144+00:00</updated>
    <content>EUVD-2026-333858</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-333858"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-60002</id>
    <title>fkie_cve-2026-60002</title>
    <updated>2026-10-02T15:28:02.937155+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-60002"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-gp5v-jg37-fvg6</id>
    <title>GHSA-gp5v-jg37-fvg6</title>
    <updated>2026-10-02T15:28:02.937176+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-gp5v-jg37-fvg6"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-60002</id>
    <title>msrc_CVE-2026-60002 — ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This…</title>
    <updated>2026-10-02T15:28:02.937189+00:00</updated>
    <content>msrc_CVE-2026-60002</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-60002"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ncsc-2026-0321</id>
    <title>NCSC-2026-0321 — Meerdere kwetsbaarheden verholpen in IBM AIX en IBM PowerVM VIOS</title>
    <updated>2026-10-02T15:28:02.937206+00:00</updated>
    <content>NCSC-2026-0321</content>
    <link href="https://cve.radiocsirt.org/vuln/ncsc-2026-0321"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-3429</id>
    <title>OESA-2026-3429 — openssh security update</title>
    <updated>2026-10-02T15:28:02.937408+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP4: openssh</p>
<p>An open source implementation of SSH protocol version 2

Security Fix(es):</p>
<p>sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication.(CVE-2026-60000)</p>
<p>sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.(CVE-2026-60001)</p>
<p>ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)(CVE-2026-60002)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-3429"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21477-1</id>
    <title>openSUSE-SU-2026:21477-1 — Security update for openssh</title>
    <updated>2026-10-02T15:28:02.937434+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for openssh</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:21477-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:37382</id>
    <title>RHSA-2026:37382 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
    <updated>2026-10-02T15:28:02.937455+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>openssh: OpenSSH: sftp client allows attacker to control downloaded file location openssh: OpenSSH: `scp` file misplacement vulnerability during remote copy openssh: OpenSSH: SFTP security bypass due to command-line argument parsing flaw openssh: OpenSSH: Undocumented GSSAPIStrictAcceptorCheck behavior impacts security in Windows Active Directory openssh: OpenSSH sshd: Security bypass due to incorrect handling of forwarding and tunneling options openssh: OpenSSH: Denial of Service via excessive GSSAPI authentication attempts openssh: OpenSSH: Brute-force attacks facilitated due to insufficient authentication delay openssh: OpenSSH: Use-after-free vulnerability during host key re-exchange on the client side</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:37382"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:47756</id>
    <title>RLSA-2026:47756 — Important: openssh security update</title>
    <updated>2026-10-02T15:28:02.937483+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:9: openssh</p>
<p>OpenSSH is an SSH protocol implementation supported by a number of Linux, UNIX, and similar operating systems. It includes the core files necessary for both the OpenSSH client and server.</p>
<p>Security Fix(es):</p>
<p>* openssh: Local MITM of X11 forwarding via abstract UNIX socket pre-binding in Rocky Linux OpenSSH client versions (CVE-2026-55655)</p>
<p>* openssh: Double free in Rocky Linux versions of OpenSSH DH-GEX client path during FIPS known-group validation leads to client-side denial of service (CVE-2026-55653)</p>
<p>* openssh: Heap out-of-bounds read in Rocky Linux versions of OpenSSH GSSAPI indicator cleanup due to missing NULL sentinel termination (CVE-2026-55654)</p>
<p>* openssh: OpenSSH: Use-after-free vulnerability during host key re-exchange on the client side (CVE-2026-60002)</p>
<p>* openssh: OpenSSH: `scp` file misplacement vulnerability during remote copy (CVE-2026-59996)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:47756"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:22978-1</id>
    <title>SUSE-SU-2026:22978-1 — Security update for openssh</title>
    <updated>2026-10-02T15:28:02.937510+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for openssh</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:22978-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-60002</id>
    <title>UBUNTU-CVE-2026-60002</title>
    <updated>2026-10-02T15:28:02.937529+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:FIPS:16.04:LTS: openssh, Ubuntu:18.04:LTS: openssh-ssh1, Ubuntu:Pro:FIPS-updates:18.04:LTS: openssh, Ubuntu:Pro:FIPS:18.04:LTS: openssh, Ubuntu:20.04:LTS: openssh-ssh1, Ubuntu:Pro:FIPS-updates:20.04:LTS: openssh, Ubuntu:Pro:FIPS:20.04:LTS: openssh, Ubuntu:22.04:LTS: openssh, Ubuntu:22.04:LTS: openssh-ssh1, Ubuntu:Pro:FIPS-preview:22.04:LTS: openssh and 8 more</p>
<p>ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-60002"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2221</id>
    <title>WID-SEC-W-2026-2221 — OpenSSH: Mehrere Schwachstellen</title>
    <updated>2026-10-02T15:28:02.937570+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in OpenSSH ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, und um Sicherheitsvorkehrungen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2221"/>
  </entry>
</feed>
