USN-8533-1: OpenSSH vulnerabilities
It was discovered that OpenSSH sftp did not properly constrain the location of downloaded files when connecting to an attacker-controlled server. An attacker could possibly use this issue to write files to unintended locations on the file system. (CVE-2026-59995) It was discovered that OpenSSH scp could place files in the parent directory of the intended destination when copying between two remote hosts. An attacker could possibly use this issue to write files to unintended locations. (CVE-2026-59996) It was discovered that OpenSSH internal-sftp only recognized the first nine command-line arguments, This could result in certain security-sensitive arguments being ignored, contrary to expectations. (CVE-2026-59997) It was discovered that OpenSSH had undocumented behaviour regarding the GSSAPIStrictAcceptorCheck option in environments using Windows Active Directory. The documentation has been updated to clarify use of the option. (CVE-2026-59998) It was discovered that OpenSSH did not properly enforce precedence of DisableForwarding=yes over PermitTunnel=yes in server configurations. This could possibly result in intended network forwarding restrictions being bypassed, contrary to expectations. (CVE-2026-59999) It was discovered that OpenSSH mishandled the MaxAuthTries limit for GSSAPI authentication. A remote attacker could use this issue to perform excessive authentication attempts. (CVE-2026-60000) It was discovered that OpenSSH did not always honour the minimum authentication delay. An attacker could possibly use this issue to perform brute-force attacks more efficiently. (CVE-2026-60001) It was discovered that the OpenSSH client had a use-after-free vulnerability when a server changed its host key during a key re-exchange. An attacker able to intercept communications could possibly use this issue to execute arbitrary code or obtain sensitive information. (CVE-2026-60002)
CSIRTS triage
- What
- OpenSSH has multiple vulnerabilities that could allow an attacker to write files to unintended locations or ignore security-sensitive command-line arguments.
- Who is affected
- Users of OpenSSH, particularly those using sftp and scp functionalities.
- Urgency
- Remediation is urgent due to the potential for exploitation and the impact on file system integrity.
- Action
- Update to the latest version of OpenSSH to mitigate these vulnerabilities.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch OpenSSH
Get an email when a new OpenSSH advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://ubuntu.com/security/notices/USN-8533-1
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-599950.25% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 17% of all scored CVEs.
- Low exploitation riskCVE-2026-599960.25% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 17% of all scored CVEs.
- Low exploitation riskCVE-2026-599970.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all scored CVEs.
- Low exploitation riskCVE-2026-599980.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 8% of all scored CVEs.
- Low exploitation riskCVE-2026-599990.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all scored CVEs.
- Low exploitation riskCVE-2026-600000.44% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 36% of all scored CVEs.
- Low exploitation riskCVE-2026-600010.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all scored CVEs.
- Low exploitation riskCVE-2026-600020.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 22% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-59995 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-59996 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-59997 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-59998 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-59999 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-60000 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-60001 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-60002 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownMultiple vulnerabilities in Microsoft Azure Linux (July 15, 2026)cert-fr-avis
- mediumCVE-2026-59995: sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when …msrc
- lowCVE-2026-60000: sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource con…msrc
- mediumCVE-2026-59999: In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over Per…msrc
- mediumCVE-2026-59998: sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAccept…msrc
- mediumCVE-2026-59997: internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line argument…msrc
- mediumCVE-2026-60001: sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.msrc
- highCVE-2026-60002: ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during…msrc
- mediumCVE-2026-59996: scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory w…msrc
- highCVE-2026-60002: ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during…nvd
- mediumCVE-2026-60001: sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.nvd
- lowCVE-2026-60000: sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource con…nvd
More from Ubuntu Security Notices
- highUSN-8620-4: Linux kernel (Intel IoTG) vulnerabilities2026-07-31
- highUSN-8620-3: Linux kernel (Intel IoTG) vulnerabilities2026-07-31
- unknownUSN-8625-1: OpenSSL vulnerability2026-07-30
- unknownUSN-8624-1: Sinatra vulnerability2026-07-29
- unknownUSN-8623-1: Linux kernel (NVIDIA) vulnerabilities2026-07-29