Openbsd
- 3
- vulnerabilities tracked
- 1
- critical
- 8 July 2026
- latest publication
cve
Vulnerability watch
idvulnerabilityseveritypublished
CVE-2026-59999In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.Openbsd Openssh High CVSS 7.5 CVE-2026-60000sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication.Openbsd Openssh High CVSS 7.5 CVE-2026-60002ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)Openbsd Openssh Critical CVSS 9.4