CVE-2026-59997General(openbsd / openssh)

LOWCVSS 5.4 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch openbsd openssh systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openssh

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 4 mentions (2026-07-08); latest day: 1
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
openssh

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-07-08: 4Mentions · 2026-07-10: 1Patch / Workaround · 2026-07-08: 2Technical Details · 2026-07-08: 207-0807-10
Signal classification3 categories
General
240.0%
Patch
240.0%
Disclosure
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-07-084
Disclosure1General1Patch2
2026-07-101
General1
Full discourse5 posts
  • yousukezan@yousukezan
    Patch

    OpenSSHの脆弱性(Moderate: CVE-2026-59995, CVE-2026-59996, CVE-2026-59997, CVE-2026-59998, CVE-2026-59999)とOpenSSH 10.4/10.4p1リリース https://security.sios.jp/vulnerability/openssh-security-vulnerability-20260709/

    Post summary

    The post announces the release of OpenSSH 10.4/10.4p1, which addresses several moderate CVEs, without providing exploit details or evidence of active attacks.

    0301341.8K
    14.9K followersView on X
  • Kazuki Omo@omokazuki
    Patch

    OpenSSHの脆弱性(Moderate: CVE-2026-59995, CVE-2026-59996, CVE-2026-59997, CVE-2026-59998, CVE-2026-59999)とOpenSSH 10.4/10.4p1リリース #sios_tech #security #vulnerability #セキュリティ #脆弱性 #linux #openssh #ssh https://security.sios.jp/vulnerability/openssh-security-vulnerability-20260709/

    Post summary

    The post alerts that five moderate CVEs affect OpenSSH and announces the release of OpenSSH 10.4/10.4p1 as the fix.

    00010148
    369 followersView on X
  • connect24h@connect24h
    General

    OpenSSH 10.4複数CVE https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59997

    Post summary

    The source lists an OpenSSH 10.4 vulnerability and links to a Microsoft update guide, but provides no information on exploitation, mitigation, or technical specifics.

    00000187
    4.4K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-59997 internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have he… https://www.cve.org/CVERecord?id=CVE-2026-59997 ----- Traducción: CVE-2026-59997 int… http://infoflow.cloud`

    Post summary

    A brief disclosure of CVE‑2026‑59997, an OpenSSH pre‑10.4 flaw where internal‑sftp limits processing to the first nine command‑line arguments.

    0000044
    91 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-59997 internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have he… https://www.cve.org/CVERecord?id=CVE-2026-59997

    Post summary

    The text provides a brief technical description of CVE-2026-59997 in OpenSSH, noting argument handling issues, but offers no exploit proof, active usage claim, or patch information.

    00000665
    57.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenbsdopenssh---

Explore more