CVE-2026-59999Disclosure(openbsd / openssh)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch openbsd openssh systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-348

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openssh

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 4 mentions (2026-07-08); latest day: 1
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
openssh

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-07-08: 4Mentions · 2026-07-10: 1Patch / Workaround · 2026-07-08: 2Technical Details · 2026-07-08: 3Technical Details · 2026-07-10: 107-0807-10
Signal classification3 categories
Disclosure
360.0%
General
120.0%
Patch
120.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-07-084
Disclosure2General1Patch1
2026-07-101
Disclosure1
Full discourse5 posts
  • yousukezan@yousukezan
    Disclosure

    OpenSSHの脆弱性(Moderate: CVE-2026-59995, CVE-2026-59996, CVE-2026-59997, CVE-2026-59998, CVE-2026-59999)とOpenSSH 10.4/10.4p1リリース https://security.sios.jp/vulnerability/openssh-security-vulnerability-20260709/

    Post summary

    The post announces a set of moderate severity OpenSSH CVEs and the release of version 10.4/10.4p1, indicating a patch, but provides no further technical or exploit details.

    0301341.8K
    14.9K followersView on X
  • Mohi@disismohi
    Disclosure

    CVE-2026-59999: OpenSSH before 10.4 ignored DisableForwarding=yes when PermitTunnel=yes was also set. Your bastion config might have been lying to you.

    Post summary

    The post details a configuration flaw in OpenSSH ≤10.4 where DisableForwarding=yes is ignored if PermitTunnel=yes, representing a disclosure of a new vulnerability.

    1000056
    72 followersView on X
  • Kazuki Omo@omokazuki
    Patch

    OpenSSHの脆弱性(Moderate: CVE-2026-59995, CVE-2026-59996, CVE-2026-59997, CVE-2026-59998, CVE-2026-59999)とOpenSSH 10.4/10.4p1リリース #sios_tech #security #vulnerability #セキュリティ #脆弱性 #linux #openssh #ssh https://security.sios.jp/vulnerability/openssh-security-vulnerability-20260709/

    Post summary

    The post announces the release of OpenSSH 10.4/10.4p1, which includes patches for five moderate‐severity CVEs (CVE‑2026‑59995 through CVE‑2026‑59999).

    00010148
    369 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-59999 In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not. https://www.cve.org/CVERecord?id=CVE-2026-59999

    Post summary

    The CVE details a configuration precedence issue in OpenSSH that allows tunnels when forwarding is disabled; no exploitation or patches are referenced.

    00010720
    57.8K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-59999 In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not. https://www.cve.org/CVERecord?id=CVE-2026-59999 ----- Traducción: CVE-2026-59999 En sshd de OpenSSH anterior a 10.4, DisableForward… http://infoflow.cloud`

    Post summary

    CVE-2026-59999 highlights a precedence issue in OpenSSH sshd pre‑10.4 where DisableForwarding=yes fails to override PermitTunnel=yes, potentially allowing unintended tunneling.

    0000037
    91 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenbsdopenssh---

Explore more