<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 11:33:00 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:69129 — Important: openssh security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:69129</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: openssh, AlmaLinux:10: openssh-askpass, AlmaLinux:10: openssh-clients, AlmaLinux:10: openssh-keycat, AlmaLinux:10: openssh-keysign, AlmaLinux:10: openssh-server&lt;/p&gt;
&lt;p&gt;OpenSSH is an SSH protocol implementation supported by a number of Linux, UNIX, and similar operating systems. It includes the core files necessary for both the OpenSSH client and server.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* openssh: OpenSSH: sftp client allows attacker to control downloaded file location (CVE-2026-59995)
  * openssh: OpenSSH sshd: Security bypass due to incorrect handling of forwarding and tunneling options (CVE-2026-59999)
  * openssh: OpenSSH: Tunnel forwarding restriction bypass (CVE-2026-73283)
  * openssh: OpenSSH: ssh-agent allows remote execution of local operations (CVE-2026-73281)
  * openssh: OpenSSH: Information disclosure and data corruption via use-after-free in ssh client (CVE-2026-73282)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: openssh, AlmaLinux:10: openssh-askpass, AlmaLinux:10: openssh-clients, AlmaLinux:10: openssh-keycat, AlmaLinux:10: openssh-keysign, AlmaLinux:10: openssh-server&lt;/p&gt;
&lt;p&gt;OpenSSH is an SSH protocol implementation supported by a number of Linux, UNIX, and similar operating systems. It includes the core files necessary for both the OpenSSH client and server.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* openssh: OpenSSH: sftp client allows attacker to control downloaded file location (CVE-2026-59995)
  * openssh: OpenSSH sshd: Security bypass due to incorrect handling of forwarding and tunneling options (CVE-2026-59999)
  * openssh: OpenSSH: Tunnel forwarding restriction bypass (CVE-2026-73283)
  * openssh: OpenSSH: ssh-agent allows remote execution of local operations (CVE-2026-73281)
  * openssh: OpenSSH: Information disclosure and data corruption via use-after-free in ssh client (CVE-2026-73282)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:69129</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-73281</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-73281</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: openssh, Alpaquita:25: openssh, Alpaquita:stream: openssh, BellSoft Hardened Containers:23: openssh, BellSoft Hardened Containers:25: openssh, BellSoft Hardened Containers:stream: openssh&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: openssh, Alpaquita:25: openssh, Alpaquita:stream: openssh, BellSoft Hardened Containers:23: openssh, BellSoft Hardened Containers:25: openssh, BellSoft Hardened Containers:stream: openssh&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-73281</guid>
    </item>
    <item>
      <title>EUVD-2026-351275</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-351275</link>
      <description>EUVD-2026-351275</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-351275</guid>
    </item>
    <item>
      <title>fkie_cve-2026-73281</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-73281</link>
      <description>&lt;p&gt;In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-73281</guid>
    </item>
    <item>
      <title>GHSA-j58v-28m8-49f3</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-j58v-28m8-49f3</link>
      <description>&lt;p&gt;In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-j58v-28m8-49f3</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-73281 — In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, includ…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-73281</link>
      <description>msrc_CVE-2026-73281</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-73281</guid>
    </item>
    <item>
      <title>OESA-2026-3673 — openssh security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-3673</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: openssh&lt;/p&gt;
&lt;p&gt;An open source implementation of SSH protocol version 2&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the (CVE-2026-73281)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: openssh&lt;/p&gt;
&lt;p&gt;An open source implementation of SSH protocol version 2&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the (CVE-2026-73281)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-3673</guid>
    </item>
    <item>
      <title>RHSA-2026:69129 — Red Hat Security Advisory: openssh security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:69129</link>
      <description>&lt;p&gt;openssh: OpenSSH: sftp client allows attacker to control downloaded file location openssh: OpenSSH sshd: Security bypass due to incorrect handling of forwarding and tunneling options openssh: OpenSSH: ssh-agent allows remote execution of local operations openssh: OpenSSH: Information disclosure and data corruption via use-after-free in ssh client openssh: OpenSSH: Tunnel forwarding restriction bypass&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;openssh: OpenSSH: sftp client allows attacker to control downloaded file location openssh: OpenSSH sshd: Security bypass due to incorrect handling of forwarding and tunneling options openssh: OpenSSH: ssh-agent allows remote execution of local operations openssh: OpenSSH: Information disclosure and data corruption via use-after-free in ssh client openssh: OpenSSH: Tunnel forwarding restriction bypass&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:69129</guid>
    </item>
    <item>
      <title>RHSA-2026:70719 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:70719</link>
      <description>&lt;p&gt;openssh: OpenSSH: ssh-agent allows remote execution of local operations openssh: OpenSSH: Information disclosure and data corruption via use-after-free in ssh client openssh: OpenSSH: Tunnel forwarding restriction bypass&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;openssh: OpenSSH: ssh-agent allows remote execution of local operations openssh: OpenSSH: Information disclosure and data corruption via use-after-free in ssh client openssh: OpenSSH: Tunnel forwarding restriction bypass&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:70719</guid>
    </item>
    <item>
      <title>RLSA-2026:69129 — Important: openssh security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:69129</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: openssh&lt;/p&gt;
&lt;p&gt;OpenSSH is an SSH protocol implementation supported by a number of Linux, UNIX, and similar operating systems. It includes the core files necessary for both the OpenSSH client and server.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* openssh: OpenSSH: sftp client allows attacker to control downloaded file location (CVE-2026-59995)&lt;/p&gt;
&lt;p&gt;* openssh: OpenSSH sshd: Security bypass due to incorrect handling of forwarding and tunneling options (CVE-2026-59999)&lt;/p&gt;
&lt;p&gt;* openssh: OpenSSH: Tunnel forwarding restriction bypass (CVE-2026-73283)&lt;/p&gt;
&lt;p&gt;* openssh: OpenSSH: ssh-agent allows remote execution of local operations (CVE-2026-73281)&lt;/p&gt;
&lt;p&gt;* openssh: OpenSSH: Information disclosure and data corruption via use-after-free in ssh client (CVE-2026-73282)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: openssh&lt;/p&gt;
&lt;p&gt;OpenSSH is an SSH protocol implementation supported by a number of Linux, UNIX, and similar operating systems. It includes the core files necessary for both the OpenSSH client and server.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* openssh: OpenSSH: sftp client allows attacker to control downloaded file location (CVE-2026-59995)&lt;/p&gt;
&lt;p&gt;* openssh: OpenSSH sshd: Security bypass due to incorrect handling of forwarding and tunneling options (CVE-2026-59999)&lt;/p&gt;
&lt;p&gt;* openssh: OpenSSH: Tunnel forwarding restriction bypass (CVE-2026-73283)&lt;/p&gt;
&lt;p&gt;* openssh: OpenSSH: ssh-agent allows remote execution of local operations (CVE-2026-73281)&lt;/p&gt;
&lt;p&gt;* openssh: OpenSSH: Information disclosure and data corruption via use-after-free in ssh client (CVE-2026-73282)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:69129</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-73281</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-73281</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: openssh, Ubuntu:Pro:16.04:LTS: openssh, Ubuntu:Pro:FIPS:16.04:LTS: openssh, Ubuntu:Pro:18.04:LTS: openssh, Ubuntu:18.04:LTS: openssh-ssh1, Ubuntu:Pro:FIPS-updates:18.04:LTS: openssh, Ubuntu:Pro:FIPS:18.04:LTS: openssh, Ubuntu:Pro:20.04:LTS: openssh, Ubuntu:20.04:LTS: openssh-ssh1, Ubuntu:Pro:FIPS-updates:20.04:LTS: openssh and 10 more&lt;/p&gt;
&lt;p&gt;In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: openssh, Ubuntu:Pro:16.04:LTS: openssh, Ubuntu:Pro:FIPS:16.04:LTS: openssh, Ubuntu:Pro:18.04:LTS: openssh, Ubuntu:18.04:LTS: openssh-ssh1, Ubuntu:Pro:FIPS-updates:18.04:LTS: openssh, Ubuntu:Pro:FIPS:18.04:LTS: openssh, Ubuntu:Pro:20.04:LTS: openssh, Ubuntu:20.04:LTS: openssh-ssh1, Ubuntu:Pro:FIPS-updates:20.04:LTS: openssh and 10 more&lt;/p&gt;
&lt;p&gt;In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-73281</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2747 — OpenSSH: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2747</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenSSH ausnutzen, um Sicherheitsvorkehrungen zu umgehen, einen Denial of Service und potentiell Codeausführung zu erreichen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenSSH ausnutzen, um Sicherheitsvorkehrungen zu umgehen, einen Denial of Service und potentiell Codeausführung zu erreichen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2747</guid>
    </item>
  </channel>
</rss>
