CVE-2026-59998Disclosure(openbsd / openssh)

LOWCVSS 6.5 · MEDIUM

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch openbsd openssh systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-573

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openssh

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • 4 total mentions across 1 day

Affected systems

Vendors
Products
openssh

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-07-08: 4Patch / Workaround · 2026-07-08: 2Technical Details · 2026-07-08: 207-08
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets3 URLs
Full discourse4 posts
  • yousukezan@yousukezan
    Disclosure

    OpenSSHの脆弱性(Moderate: CVE-2026-59995, CVE-2026-59996, CVE-2026-59997, CVE-2026-59998, CVE-2026-59999)とOpenSSH 10.4/10.4p1リリース https://security.sios.jp/vulnerability/openssh-security-vulnerability-20260709/

    Post summary

    The post announces that several moderate CVEs have been identified in OpenSSH and directs readers to a new release (10.4/10.4p1) that presumably patches the issues.

    0301341.8K
    14.9K followersView on X
  • Kazuki Omo@omokazuki
    Patch

    OpenSSHの脆弱性(Moderate: CVE-2026-59995, CVE-2026-59996, CVE-2026-59997, CVE-2026-59998, CVE-2026-59999)とOpenSSH 10.4/10.4p1リリース #sios_tech #security #vulnerability #セキュリティ #脆弱性 #linux #openssh #ssh https://security.sios.jp/vulnerability/openssh-security-vulnerability-20260709/

    Post summary

    OpenSSH Moderate vulnerabilities CVE-2026-59995 to 59999 are disclosed and have been addressed in the OpenSSH 10.4/10.4p1 release.

    00010148
    369 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-59998 sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory. https://www.cve.org/CVERecord?id=CVE-2026-59998

    Post summary

    CVE‑2026‑59998 discloses that OpenSSH before 10.4 ignores the GSSAPIStrictAcceptorCheck setting when the server runs in a Windows Active Directory environment.

    00010748
    57.8K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-59998 sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory. https://www.cve.org/CVERecord?id=CVE-2026-59998 ----- Traducción: CVE-2026-59998 sshd en Ope… http://infoflow.cloud`

    Post summary

    The text discloses technical details of CVE‑2026‑59998, describing an undocumented OpenSSH behavior without mentioning exploits, patches, or active use.

    0000042
    91 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenbsdopenssh---

Explore more