#OpenSSH's
VSCode’s SSH Agent Is Bananas. What could go possibly wrong? Of course, it is not OpenSSH's problem. It is the software company's poor implementation. You have to choose what is best for you. Security should always be a priority, and remember the KISS principle.
February 8, 2025 at 5:48 AM
MitM attack against OpenSSH's VerifyHostKeyDNS-enabled client : seclists.org/fulldisclosu...
Full Disclosure: Re: MitM attack against OpenSSH's VerifyHostKeyDNS-enabled client
seclists.org
March 3, 2025 at 3:15 PM
We published this on Wednesday, in case you missed it: OpenSSH 10.6 Released With Security Fixes and a Dozen New Features - FOSS Force buff.ly/oXlqL8R
OpenSSH 10.6 Released With Security Fixes and a Dozen New Features - FOSS Force
OpenSSH’s update brings broader post-quantum warnings, a new username restriction, and some thoughts on security reporting in the age of AI.
buff.ly
October 8, 2026 at 8:00 PM
We should stop adding these RCE things to important software, they seem a bit dangerous.

(also "...on glibc-based Linux systems" @shreyanjain.net onto something 🤔)
oss-security - Re: CVE-2024-6387: RCE in OpenSSH's server, on glibc-based Linux systems
www.openwall.com
July 9, 2024 at 7:22 PM
Qualys Security Advisory

CVE-2025-26465: MitM attack against OpenSSH's VerifyHostKeyDNS-enabled
client

CVE-2025-26466: DoS attack against OpenSSH's client and server


www.openwall.com ->


Original->
February 18, 2025 at 9:22 AM
[Foss Force] OpenSSH 10.6 Released With Security Fixes and a Dozen New Features

#FOSS #InfoSec
OpenSSH 10.6 Released With Security Fixes and a Dozen New Features
OpenSSH’s latest update brings broader post-quantum warnings, a new username restriction, and some thoughts on security reporting in the age of AI. The post OpenSSH 10.6 Released With Security Fixes…
www.linuxnews.net
October 7, 2026 at 6:30 PM
Re: MitM attack against OpenSSH's VerifyHostKeyDNS-enabled client
Re: MitM attack against OpenSSH's VerifyHostKeyDNS-enabled client
Posted by Qualys Security Advisory on Feb 21 Hi Jordy, Woo-hoo, awesome work, thank you very much for sharing it! We are looking into it now (and learning from it). Thanks again! With best regards,
seclists.org
February 21, 2025 at 6:15 PM
Technical Analysis Published for OpenSSH’s Agent Forwarding RCE Vulnerability
Technical Analysis Published for OpenSSH's Agent Forwarding RCE Vulnerability
cybersecuritynews.com
March 31, 2025 at 4:01 PM
⚠️ PSA: Update your OpenSSH on clients and servers, today (as soon as vendors have updates). https://blog.qualys.com/vulnerabilities-threat-research/2023/07/19/cve-2023-38408-remote-code-execution-in-opensshs-forwarded-ssh-agent

(If you don’t know what OpenSSH is, you’re probably fine or fucked.)
CVE-2023-38408: Remote Code Execution in OpenSSH’s forwarded ssh-agent – Qualys Security BlogTwi...
blog.qualys.com
July 19, 2023 at 9:35 PM
Heads up: regreSSHion: Remote Unauthenticated Code Execution Vulnerability in OpenSSH server. Patch your server ASAP. blog.qualys.com/vulnerabilit... also see my openssh security guide for more info www.cyberciti.biz/tips/linux-u...
regreSSHion: Remote Unauthenticated Code Execution Vulnerability in OpenSSH server | Qualys Security Blog
The Qualys Threat Research Unit (TRU) has discovered a Remote Unauthenticated Code Execution (RCE) vulnerability in OpenSSH’s server (sshd) in glibc-based Linux systems. CVE assigned to this…
blog.qualys.com
July 1, 2024 at 12:42 PM
MitM attack against OpenSSH's VerifyHostKeyDNS-enabled client

seclists.org/oss-sec/2025...
oss-sec: MitM attack against OpenSSH's VerifyHostKeyDNS-enabled client
seclists.org
February 18, 2025 at 10:30 AM
Over 14M servers may be vulnerable to OpenSSH's regreSSHion RCE flaw. Here's what you need to do zdnet.com/article/over... by @sjvn.bsky.social

You may not be able to patch this #Linux-related #security hole today, but there is another way of dealing with it. CVE-2024-6387.
Over 14M servers may be vulnerable to OpenSSH's regreSSHion RCE flaw. Here's what you need to do
OpenSSH, the bedrock of secure Linux network access, has a nasty security flaw.
zdnet.com
July 2, 2024 at 7:27 PM
Erm, oh dear. Glibc-based Linux systems are vulnerable to a remote-code execution attack (CVE-2024-6387) in OpenSSH's server (sshd) and should upgrade to the latest version

www.theregister.com/2024/07/01/r...
Nasty regreSSHion bug affects around 700K Linux systems
Full system takeovers on the cards, for those with enough patience to pull it off
www.theregister.com
July 1, 2024 at 8:57 PM
A Single Line of Code: Pre-Auth OpenSSH Flaw Exposes Ubuntu and Debian Servers
A Single Line of Code: Pre-Auth OpenSSH Flaw Exposes Ubuntu and Debian Servers
A pre-auth flaw in OpenSSH's GSSAPI Key Exchange (CVE-2026-3497) exposes Ubuntu and Debian servers to heap corruption and data leaks. Patch now.
securityonline.info
March 13, 2026 at 4:26 AM
“CVE-2024-6387 arises from a signal handler race condition in OpenSSH’s server (sshd). This issue occurs when an unauthenticated client fails to log in within the `LoginGraceTime` limit (120 seconds by default).”
cybersecuritynews.com/regresshion-...
PoC Exploit Released For OpenSSH Arbitrary Code Execution Vulnerability
A proof-of-concept (PoC) exploit for the critical OpenSSH vulnerability CVE-2024-6387, also known as "regreSSHion," has been released, raising alarms across the cybersecurity community.
cybersecuritynews.com
January 6, 2025 at 11:41 PM
18年前に報告・修正されていたOpenSSHの重要な脆弱性が実は3年前だか4年前だかにデグレって再発していたのが発覚して騒ぎになるの、人間味がある
blog.qualys.com/vulnerabilit...
regreSSHion: Remote Unauthenticated Code Execution Vulnerability in OpenSSH server | Qualys Security Blog
The Qualys Threat Research Unit (TRU) has discovered a Remote Unauthenticated Code Execution (RCE) vulnerability in OpenSSH’s server (sshd) in glibc-based Linux systems. CVE assigned to this…
blog.qualys.com
July 1, 2024 at 3:00 PM
CVE-2026-59999: OpenSSH's Mishandled Settings Leave Users Exposed #OpenSSH #CyberSecurity #CVE2026
CVE-2026-59999: OpenSSH's Mishandled Settings Leave Users Exposed
CVE-2026-59999 reveals flaws in OpenSSH prior to 10.4, mismanaging DisableForwarding and PermitTunnel settings, compromising security.
cybernewsroom.xyz
July 9, 2026 at 1:42 PM
RCE in OpenSSH's server
www.qualys.com
July 26, 2024 at 4:35 PM
CVE-2026-59999 Exposes Flaw in OpenSSH's Configuration Priority — Audit Now #OpenSSH #CVE2026 #CyberSecurity
CVE-2026-59999 Exposes Flaw in OpenSSH's Configuration Priority — Audit Now
CVE-2026-59999 reveals a critical vulnerability in OpenSSH affecting secure tunneling. Organizations must audit configurations to prevent unauthorized access.
cybernewsroom.xyz
July 9, 2026 at 1:40 PM
July 19, 2023 at 4:58 PM