CVE-2026-73281
In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.
CSIRTS triage
- What
- SSH agent allows remote operations intended to be local-only due to session-bind extension mishandling.
- Who is affected
- Systems running OpenSSH versions before 10.5 with ssh-agent in use are affected.
- Urgency
- Low severity with CVSS 3.5; remediation can follow standard patch cycles.
- Action
- Upgrade to OpenSSH 10.5 or later.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-73281
Get an email if CVE-2026-73281 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all EPSS-scored CVEs.
Advisory coverage (2)
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-73281)