CVE-2026-44405Disclosure

LOWCVSS 3.4 · LOW

Exploit discussion active in current signal (4 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

In Paramiko through 4.0.0 before a448945, rsakey.py allows the SHA-1 algorithm.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-327

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Threat summary

  • Public PoC is present in monitored signal
  • 4 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 4 total mentions across 1 day

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-05-06: 4PoC Mentioned / Linked · 2026-05-06: 2Technical Details · 2026-05-06: 305-06
Signal classification2 categories
Disclosure
375.0%
PoC
125.0%
Referenced assets4 URLs
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-44405 In Paramiko through 4.0.0 before a448945, http://rsakey.py allows the SHA-1 algorithm. https://www.cve.org/CVERecord?id=CVE-2026-44405

    Post summary

    CVE-2026-44405 affects Paramiko versions before 4.0.0, and a script (http://rsakey.py) demonstrates the SHA‑1 algorithm usage; no patch or active exploitation is mentioned.

    00010258
    57.4K followersView on X
  • NerdieNews@NewsNerdie
    Disclosure

    ⚠️ CVE-2026-44405 lets attackers exploit Paramiko with outdated SHA-1 for RSA keys, risking data integrity. Revoke access today to mitigate potential threats. #NerdieNews #CyberSecurity #InfoSec #Ransomware #Malware #Microsoft #Google https://t.co/g9HNyUQS5u

    Post summary

    The tweet announces CVE‑2026‑44405, detailing how attackers can exploit Paramiko’s use of SHA‑1 for RSA keys, and urges immediate revocation of access to mitigate potential data integrity threats.

    0000042
    57 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-44405 SHA-1 Algorithm Vulnerability in Paramiko Through Version 4.0.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-44405

    Post summary

    The text announces CVE‑2026‑44405, a SHA‑1 algorithm vulnerability in Paramiko up to version 4.0.0, but provides no additional technical, exploit, or patch information.

    0000046
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    PoC

    🚨*CVE* CVE-2026-44405 In Paramiko through 4.0.0 before a448945, http://rsakey.py allows the SHA-1 algorithm. https://www.cve.org/CVERecord?id=CVE-2026-44405 ----- Traducción: CVE-2026-44405 En Paramiko hasta la versión 4.0.0 antes de a448945, http://rsakey.py p… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑44405 in Paramiko and supplies a link to a script that demonstrates the SHA‑1 related vulnerability, but it does not provide evidence of a functional exploit or active attacks.

    0000036
    75 followersView on X

Explore more