PT-2026-56293 · Openssh+4 · Openssh+4

CVE-2026-60002

·

Published

2026-07-08

·

Updated

2026-08-30

CVSS v3.1

9.4

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions OpenSSH versions prior to 10.4
Description A use-after-free issue exists in the ssh client. This occurs when a server changes its host key during a key re-exchange, which is a process where the client and server negotiate new session keys to maintain security.
Recommendations Update to version 10.4 or later.

Exploit

Fix

DoS

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:47756
ALSA-2026:47757
AZL-92054
CVE-2026-60002
ECHO-F3C1-98DB-8B17
JLSEC-2026-1326
OESA-2026-3429
OESA-2026-3565
OESA-2026-3566
OESA-2026-3567
OESA-2026-3568
OPENSUSE-SU-2026:21477-1
SUSE-SU-2026:22978-1
SUSE-SU-2026:3605-1
USN-8533-1

Affected Products

Ibm Aix
Linuxmint
Openssh
Rocky Linux
Ubuntu