
OpenSSH 10.3p1 fixed two issues we reported: CVE-2026-35385 in scp and CVE-2026-35387 in ECDSA policy handling. Different bugs, same lesson: mature infrastructure still carries security debt that only shows up when someone re-reads the assumptions.
Post summary
The note announces that OpenSSH 10.3p1 has patched two CVEs affecting scp and ECDSA policy handling, with no evidence of active exploitation or exposure of PoC details.


