<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 05:34:28 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:47756 — Important: openssh security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:47756</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: openssh, AlmaLinux:9: openssh-askpass, AlmaLinux:9: openssh-clients, AlmaLinux:9: openssh-keycat, AlmaLinux:9: openssh-server, AlmaLinux:9: pam_ssh_agent_auth&lt;/p&gt;
&lt;p&gt;OpenSSH is an SSH protocol implementation supported by a number of Linux, UNIX, and similar operating systems. It includes the core files necessary for both the OpenSSH client and server.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* openssh: Local MITM of X11 forwarding via abstract UNIX socket pre-binding in AlmaLinux OpenSSH client versions (CVE-2026-55655)
  * openssh: Double free in AlmaLinux versions of OpenSSH DH-GEX client path during FIPS known-group validation leads to client-side denial of service (CVE-2026-55653)
  * openssh: Heap out-of-bounds read in AlmaLinux versions of OpenSSH GSSAPI indicator cleanup due to missing NULL sentinel termination (CVE-2026-55654)
  * openssh: OpenSSH: Use-after-free vulnerability during host key re-exchange on the client side (CVE-2026-60002)
  * openssh: OpenSSH: `scp` file misplacement vulnerability during remote copy (CVE-2026-59996)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: openssh, AlmaLinux:9: openssh-askpass, AlmaLinux:9: openssh-clients, AlmaLinux:9: openssh-keycat, AlmaLinux:9: openssh-server, AlmaLinux:9: pam_ssh_agent_auth&lt;/p&gt;
&lt;p&gt;OpenSSH is an SSH protocol implementation supported by a number of Linux, UNIX, and similar operating systems. It includes the core files necessary for both the OpenSSH client and server.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* openssh: Local MITM of X11 forwarding via abstract UNIX socket pre-binding in AlmaLinux OpenSSH client versions (CVE-2026-55655)
  * openssh: Double free in AlmaLinux versions of OpenSSH DH-GEX client path during FIPS known-group validation leads to client-side denial of service (CVE-2026-55653)
  * openssh: Heap out-of-bounds read in AlmaLinux versions of OpenSSH GSSAPI indicator cleanup due to missing NULL sentinel termination (CVE-2026-55654)
  * openssh: OpenSSH: Use-after-free vulnerability during host key re-exchange on the client side (CVE-2026-60002)
  * openssh: OpenSSH: `scp` file misplacement vulnerability during remote copy (CVE-2026-59996)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:47756</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-60002</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-60002</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: openssh, Alpaquita:25: openssh, Alpaquita:stream: openssh, BellSoft Hardened Containers:23: openssh, BellSoft Hardened Containers:25: openssh, BellSoft Hardened Containers:stream: openssh&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: openssh, Alpaquita:25: openssh, Alpaquita:stream: openssh, BellSoft Hardened Containers:23: openssh, BellSoft Hardened Containers:25: openssh, BellSoft Hardened Containers:stream: openssh&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-60002</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0873 — De multiples vulnérabilités ont été découvertes dans Microsoft Azure Linux. Elles permettent à un attaquant de provoque…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0873</link>
      <description>certfr-2026-avi-0873</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0873</guid>
    </item>
    <item>
      <title>EUVD-2026-333858</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-333858</link>
      <description>EUVD-2026-333858</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-333858</guid>
    </item>
    <item>
      <title>fkie_cve-2026-60002</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-60002</link>
      <description>&lt;p&gt;ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-60002</guid>
    </item>
    <item>
      <title>GHSA-gp5v-jg37-fvg6</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-gp5v-jg37-fvg6</link>
      <description>&lt;p&gt;ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-gp5v-jg37-fvg6</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-60002 — ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-60002</link>
      <description>msrc_CVE-2026-60002</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-60002</guid>
    </item>
    <item>
      <title>NCSC-2026-0321 — Meerdere kwetsbaarheden verholpen in IBM AIX en IBM PowerVM VIOS</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0321</link>
      <description>NCSC-2026-0321</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0321</guid>
    </item>
    <item>
      <title>OESA-2026-3429 — openssh security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-3429</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: openssh&lt;/p&gt;
&lt;p&gt;An open source implementation of SSH protocol version 2&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication.(CVE-2026-60000)&lt;/p&gt;
&lt;p&gt;sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.(CVE-2026-60001)&lt;/p&gt;
&lt;p&gt;ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)(CVE-2026-60002)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: openssh&lt;/p&gt;
&lt;p&gt;An open source implementation of SSH protocol version 2&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication.(CVE-2026-60000)&lt;/p&gt;
&lt;p&gt;sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.(CVE-2026-60001)&lt;/p&gt;
&lt;p&gt;ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)(CVE-2026-60002)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-3429</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:21477-1 — Security update for openssh</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21477-1</link>
      <description>&lt;p&gt;Security update for openssh&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for openssh&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:21477-1</guid>
    </item>
    <item>
      <title>RHSA-2026:37382 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:37382</link>
      <description>&lt;p&gt;openssh: OpenSSH: sftp client allows attacker to control downloaded file location openssh: OpenSSH: `scp` file misplacement vulnerability during remote copy openssh: OpenSSH: SFTP security bypass due to command-line argument parsing flaw openssh: OpenSSH: Undocumented GSSAPIStrictAcceptorCheck behavior impacts security in Windows Active Directory openssh: OpenSSH sshd: Security bypass due to incorrect handling of forwarding and tunneling options openssh: OpenSSH: Denial of Service via excessive GSSAPI authentication attempts openssh: OpenSSH: Brute-force attacks facilitated due to insufficient authentication delay openssh: OpenSSH: Use-after-free vulnerability during host key re-exchange on the client side&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;openssh: OpenSSH: sftp client allows attacker to control downloaded file location openssh: OpenSSH: `scp` file misplacement vulnerability during remote copy openssh: OpenSSH: SFTP security bypass due to command-line argument parsing flaw openssh: OpenSSH: Undocumented GSSAPIStrictAcceptorCheck behavior impacts security in Windows Active Directory openssh: OpenSSH sshd: Security bypass due to incorrect handling of forwarding and tunneling options openssh: OpenSSH: Denial of Service via excessive GSSAPI authentication attempts openssh: OpenSSH: Brute-force attacks facilitated due to insufficient authentication delay openssh: OpenSSH: Use-after-free vulnerability during host key re-exchange on the client side&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:37382</guid>
    </item>
    <item>
      <title>RLSA-2026:47756 — Important: openssh security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:47756</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: openssh&lt;/p&gt;
&lt;p&gt;OpenSSH is an SSH protocol implementation supported by a number of Linux, UNIX, and similar operating systems. It includes the core files necessary for both the OpenSSH client and server.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* openssh: Local MITM of X11 forwarding via abstract UNIX socket pre-binding in Rocky Linux OpenSSH client versions (CVE-2026-55655)&lt;/p&gt;
&lt;p&gt;* openssh: Double free in Rocky Linux versions of OpenSSH DH-GEX client path during FIPS known-group validation leads to client-side denial of service (CVE-2026-55653)&lt;/p&gt;
&lt;p&gt;* openssh: Heap out-of-bounds read in Rocky Linux versions of OpenSSH GSSAPI indicator cleanup due to missing NULL sentinel termination (CVE-2026-55654)&lt;/p&gt;
&lt;p&gt;* openssh: OpenSSH: Use-after-free vulnerability during host key re-exchange on the client side (CVE-2026-60002)&lt;/p&gt;
&lt;p&gt;* openssh: OpenSSH: `scp` file misplacement vulnerability during remote copy (CVE-2026-59996)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: openssh&lt;/p&gt;
&lt;p&gt;OpenSSH is an SSH protocol implementation supported by a number of Linux, UNIX, and similar operating systems. It includes the core files necessary for both the OpenSSH client and server.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* openssh: Local MITM of X11 forwarding via abstract UNIX socket pre-binding in Rocky Linux OpenSSH client versions (CVE-2026-55655)&lt;/p&gt;
&lt;p&gt;* openssh: Double free in Rocky Linux versions of OpenSSH DH-GEX client path during FIPS known-group validation leads to client-side denial of service (CVE-2026-55653)&lt;/p&gt;
&lt;p&gt;* openssh: Heap out-of-bounds read in Rocky Linux versions of OpenSSH GSSAPI indicator cleanup due to missing NULL sentinel termination (CVE-2026-55654)&lt;/p&gt;
&lt;p&gt;* openssh: OpenSSH: Use-after-free vulnerability during host key re-exchange on the client side (CVE-2026-60002)&lt;/p&gt;
&lt;p&gt;* openssh: OpenSSH: `scp` file misplacement vulnerability during remote copy (CVE-2026-59996)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:47756</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:22978-1 — Security update for openssh</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:22978-1</link>
      <description>&lt;p&gt;Security update for openssh&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for openssh&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:22978-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-60002</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-60002</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:FIPS:16.04:LTS: openssh, Ubuntu:18.04:LTS: openssh-ssh1, Ubuntu:Pro:FIPS-updates:18.04:LTS: openssh, Ubuntu:Pro:FIPS:18.04:LTS: openssh, Ubuntu:20.04:LTS: openssh-ssh1, Ubuntu:Pro:FIPS-updates:20.04:LTS: openssh, Ubuntu:Pro:FIPS:20.04:LTS: openssh, Ubuntu:22.04:LTS: openssh, Ubuntu:22.04:LTS: openssh-ssh1, Ubuntu:Pro:FIPS-preview:22.04:LTS: openssh and 8 more&lt;/p&gt;
&lt;p&gt;ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:FIPS:16.04:LTS: openssh, Ubuntu:18.04:LTS: openssh-ssh1, Ubuntu:Pro:FIPS-updates:18.04:LTS: openssh, Ubuntu:Pro:FIPS:18.04:LTS: openssh, Ubuntu:20.04:LTS: openssh-ssh1, Ubuntu:Pro:FIPS-updates:20.04:LTS: openssh, Ubuntu:Pro:FIPS:20.04:LTS: openssh, Ubuntu:22.04:LTS: openssh, Ubuntu:22.04:LTS: openssh-ssh1, Ubuntu:Pro:FIPS-preview:22.04:LTS: openssh and 8 more&lt;/p&gt;
&lt;p&gt;ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-60002</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2221 — OpenSSH: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2221</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenSSH ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenSSH ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2221</guid>
    </item>
  </channel>
</rss>
