CVE-2026-35388General(openbsd / openssh)

LOWCVSS 2.5 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenSSH before 10.3 omits connection multiplexing confirmation for proxy-mode multiplexing sessions.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-420

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openssh

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-03); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
openssh

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-03: 2Mentions · 2026-04-15: 104-0304-15
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-032
Disclosure1General1
2026-04-151
General1
Full discourse3 posts
  • Kazuki Omo@omokazuki
    Disclosure

    SIOSセキュリティブログを更新しました。 OpenSSHの脆弱性(High: CVE-2026-35385, Medium: CVE-2026-35414, Low: CVE-2026-35386, CVE-2026-35387, CVE-2026-35388)と10.3/10.3p1の公開 #sios_tech #security #vulnerability #セキュリティ #脆弱性 #linux #openssh #ssh https://security.sios.jp/vulnerability/openssh-vulnerability-20260403/

    Post summary

    SIOS blog announces several new OpenSSH vulnerabilities with classified severity, but provides no PoC, exploit details, patches, or technical specifics.

    00010104
    361 followersView on X
  • WindowsForum@windowsforum
    General

    🪟 “Extra conditions” for CVE-2026-35388 usually means exploitation isn’t click-and-own—it’s click-and-recon. Translation: your network got lucky… until it doesn’t. #WindowsSecurity https://windowsforum.com/threads/cve-2026-35388-explained-why-microsoft-says-exploitation-needs-extra-conditions.413487/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #ThreatDetection #MicrosoftSecurityUpdateGuide #Cve202635388

    Post summary

    The post highlights that CVE‑2026‑35388 requires additional conditions for exploitation, suggesting it isn’t a straightforward click‑and‑own vulnerability, but provides no evidence of PoC, active exploitation, or patches.

    0000027
    1.1K followersView on X
  • IT関連サイト記事@itit7777
    General

    IT関連サイト記事が更新されました!記事はこちらから⇒ OpenSSHの脆弱性(High: CVE-2026-35385, Medium: CVE-2026-35414, Low: CVE-2026-35386, CVE-2026-35387, CVE-2026-35388)と、OpenSSH 10.3/10.3p1の公開 https://security.sios.jp/vulnerability/openssh-vulnerability-20260403/

    Post summary

    The provided text announces an article that lists several OpenSSH CVEs with their severity ratings, but it contains no technical details, exploitation evidence, or patch information.

    0000052
    446 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenbsdopenssh---

Explore more