Multiple vulnerabilities in OpenSSH (August 11, 2026)
Multiple vulnerabilities have been discovered in OpenSSH. They allow an attacker to cause an unspecified security issue by the vendor.
CSIRTS triage
- What
- Multiple vulnerabilities in OpenSSH create unspecified security issues per the vendor.
- Who is affected
- Systems running OpenSSH for remote access.
- Urgency
- Unclear urgency without vendor specification of attack vectors or severity; treat as pending update pending advisory details.
- Action
- Obtain detailed OpenSSH security advisory to determine affected versions and severity, then apply patches accordingly.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch OpenSSH
Get an email when a new OpenSSH advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0997/
Recent advisories for OpenSSH
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- medium[NEW] [medium] OpenSSH: Multiple vulnerabilitiescert-bund · 2026-08-20
- medium[UPDATE] [medium] OpenSSH: Multiple vulnerabilitiescert-bund · 2026-08-17
- high[NEW] [high] OpenSSH: Multiple vulnerabilitiescert-bund · 2026-08-11
- lowCVE-2026-73283: In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be a…nvd · 2026-08-11
- mediumCVE-2026-73282: In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair o…nvd · 2026-08-11
- lowCVE-2026-73281: In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to o…nvd · 2026-08-11
More from CERT-FR Avis de sécurité
- unknownMultiple vulnerabilities in Keycloak (August 25, 2026)2026-08-25
- unknownMultiple vulnerabilities in Cisco IOS XE (August 25, 2026)2026-08-25
- unknownMultiple vulnerabilities in LibreNMS (August 24, 2026)2026-08-24
- unknownMultiple vulnerabilities in Metabase (August 24, 2026)2026-08-24
- unknownVulnerability in SPIP (August 21, 2026)2026-08-21