CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

USN-8533-1: OpenSSH vulnerabilities

unknownCVE-2026-59995CVE-2026-59996CVE-2026-59997CVE-2026-59998CVE-2026-59999CVE-2026-60000
It was discovered that OpenSSH sftp did not properly constrain the location of downloaded files when connecting to an attacker-controlled server. An attacker could possibly use this issue to write files to unintended locations on the file system. (CVE-2026-59995) It was discovered that OpenSSH scp could place files in the parent directory of the intended destination when copying between two remote hosts. An attacker could possibly use this issue to write files to unintended locations. (CVE-2026-59996) It was discovered that OpenSSH internal-sftp only recognized the first nine command-line arguments, This could result in certain security-sensitive arguments being ignored, contrary to expectations. (CVE-2026-59997) It was discovered that OpenSSH had undocumented behaviour regarding the GSSAPIStrictAcceptorCheck option in environments using Windows Active Directory. The documentation has been updated to clarify use of the option. (CVE-2026-59998) It was discovered that OpenSSH did not properly enforce precedence of DisableForwarding=yes over PermitTunnel=yes in server configurations. This could possibly result in intended network forwarding restrictions being bypassed, contrary to expectations. (CVE-2026-59999) It was discovered that OpenSSH mishandled the MaxAuthTries limit for GSSAPI authentication. A remote attacker could use this issue to perform excessive authentication attempts. (CVE-2026-60000) It was discovered that OpenSSH did not always honour the minimum authentication delay. An attacker could possibly use this issue to perform brute-force attacks more efficiently. (CVE-2026-60001) It was discovered that the OpenSSH client had a use-after-free vulnerability when a server changed its host key during a key re-exchange. An attacker able to intercept communications could possibly use this issue to execute arbitrary code or obtain sensitive information. (CVE-2026-60002)

CSIRTS triage

What
OpenSSH has multiple vulnerabilities that could allow an attacker to write files to unintended locations or ignore security-sensitive command-line arguments.
Who is affected
Users of OpenSSH, particularly those using sftp and scp functionalities.
Urgency
Remediation is urgent due to the potential for exploitation and the impact on file system integrity.
Action
Update to the latest version of OpenSSH to mitigate these vulnerabilities.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch OpenSSH

Get an email when a new OpenSSH advisory drops — max one per day, one-click unsubscribe.

Details

Source
Ubuntu Security Notices (INTL · vendor-psirt · site)
Severity
unknown
Published
2026-07-13
Exploitation
Not in CISA KEV at last sync

Original advisory: https://ubuntu.com/security/notices/USN-8533-1

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-59995coverage & exploitation statusNVD · CVE.org
CVE-2026-59996coverage & exploitation statusNVD · CVE.org
CVE-2026-59997coverage & exploitation statusNVD · CVE.org
CVE-2026-59998coverage & exploitation statusNVD · CVE.org
CVE-2026-59999coverage & exploitation statusNVD · CVE.org
CVE-2026-60000coverage & exploitation statusNVD · CVE.org
CVE-2026-60001coverage & exploitation statusNVD · CVE.org
CVE-2026-60002coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from Ubuntu Security Notices