CVE-2026-59996Disclosure(openbsd / openssh)

LOWCVSS 5.4 · MEDIUM

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch openbsd openssh systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-23

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openssh

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • 4 total mentions across 1 day

Affected systems

Vendors
Products
openssh

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-07-08: 4Patch / Workaround · 2026-07-08: 2Technical Details · 2026-07-08: 207-08
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets3 URLs
Full discourse4 posts
  • yousukezan@yousukezan
    Patch

    OpenSSHの脆弱性(Moderate: CVE-2026-59995, CVE-2026-59996, CVE-2026-59997, CVE-2026-59998, CVE-2026-59999)とOpenSSH 10.4/10.4p1リリース https://security.sios.jp/vulnerability/openssh-security-vulnerability-20260709/

    Post summary

    The post announces several moderate‑severity CVEs affecting OpenSSH and references the 10.4/10.4p1 release that likely contains the fix.

    0301341.8K
    14.9K followersView on X
  • Kazuki Omo@omokazuki
    Disclosure

    OpenSSHの脆弱性(Moderate: CVE-2026-59995, CVE-2026-59996, CVE-2026-59997, CVE-2026-59998, CVE-2026-59999)とOpenSSH 10.4/10.4p1リリース #sios_tech #security #vulnerability #セキュリティ #脆弱性 #linux #openssh #ssh https://security.sios.jp/vulnerability/openssh-security-vulnerability-20260709/

    Post summary

    The post announces multiple OpenSSH CVE entries and references the new 10.4/10.4p1 release that presumably contains related fixes.

    00010148
    369 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-59996 scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations. https://www.cve.org/CVERecord?id=CVE-2026-59996 ----- Traducción: CVE-2026-59996 scp en OpenSSH anterior a… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-59996, detailing that scp in OpenSSH before 10.4 can place files outside their intended directory. No PoC, exploit, or patch information is provided.

    0000048
    91 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-59996 scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations. https://www.cve.org/CVERecord?id=CVE-2026-59996

    Post summary

    The post announces CVE-2026-59996, a directory‑placement issue in OpenSSH’s scp before version 10.4 that can move files to the parent directory during remote‑to‑remote copy operations.

    00000672
    57.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenbsdopenssh---

Explore more