CVE-2026-60002Disclosure(openbsd / openssh)

LOWCVSS 9.4 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch openbsd openssh systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openssh

Threat summary

  • Patch or workaround signal is available
  • 9 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 7 signals
  • Disclosure: 4 classified signals
  • Peaked 4d ago at 3 mentions (2026-07-08); latest day: 1
  • 9 total mentions across 5 days

Affected systems

Vendors
Products
openssh

Deep dive

Activity timeline9 mentions / 5d
01223Mentions · 2026-07-08: 3Mentions · 2026-07-09: 3Mentions · 2026-07-20: 1Mentions · 2026-09-17: 1Mentions · 2026-09-27: 1Patch / Workaround · 2026-07-08: 1Patch / Workaround · 2026-07-09: 3Technical Details · 2026-07-08: 3Technical Details · 2026-07-09: 3Technical Details · 2026-09-17: 107-0807-0907-2009-1709-27
Signal classification2 categories
Disclosure
450.0%
Patch
450.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-07-083
Disclosure2Patch1
2026-07-093
Patch3
2026-07-201
Disclosure1
2026-09-171
Disclosure1
Full discourse9 posts
  • PatchHawk@patchhawk_
    Patch

    The one that got a number: CVE-2026-60002, the release's only High (7.7). If a server swaps its host key mid-rekey, the client can reuse memory it just freed. That's the use-after-free. The fix makes the client own that state instead of borrowing a pointer to it. https://t.co/7zPqM2OWOS

    Post summary

    A high‑severity use‑after‑free flaw (CVE‑2026‑60002) has been disclosed; the fix changes client state ownership to prevent memory reuse.

    14040248
    60 followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    OpenSSH 10.4 ships eight security fixes, including a client use-after-free (CVE-2026-60002) plus SFTP and SCP path bugs. Update now. #OpenSSH #SSH #UseAfterFree #CVE #InfoSec #CyberSecurity http://securityonline.info/openssh-10-4-security-fixes/

    Post summary

    The post announces that OpenSSH 10.4 contains eight security fixes, including a client use‑after‑free (CVE‑2026‑60002). Users are urged to update immediately to address the vulnerability.

    11140543
    12.9K followersView on X
  • Technology Updates@DIYprojects55
    Patch

    https://pbxscience.com/openssh-patches-client-side-use-after-free-flaw-cve-2026-60002-update-now/ OpenSSH Patches Client-Side Use-After-Free Flaw (CVE-2026-60002) — Update Now. The OpenSSH project has released version 10.4 (10.4p1 for the portable build), fixing a security vulnerability tracked as CVE-2026-60002...

    Post summary

    The post announces the release of OpenSSH 10.4 and 10.4p1 to remediate a client‑side use‑after‑free vulnerability (CVE‑2026‑60002).

    0101290
    564 followersView on X
  • ThreatWire@ThreatWire_
    Patch

    🚨 CVE-2026-60002: OpenSSH 10.4 includes eight security fixes, addressing a client use-after-free vulnerability along with SFTP and SCP path handling flaws. Update now. #CyberSecurity #CVE #OpenSSH #ThreatWire

    Post summary

    The post announces a new CVE in OpenSSH 10.4 and stresses the availability of a patch that addresses a use‑after‑free and path handling vulnerabilities.

    10020124
    1.3K followersView on X
  • kuza55@kuza55

    @dinodaizovi Not really my claim, you know the saying about absence of evidence. But I just looked up the recent CVE history of OpenSSH/FIrecracker, and they definitely don't seem perfect, especially the ssh client. seL4 also still has issues outside the proven core. CVE-2026-60002 was AI

    1001084
    3.2K followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidad en productos OpenSSH ❗ CVE-2026-60002 ➡️ Más info: https://www.cert.gov.py/vulnerabilidad-en-productos-openssh/ https://t.co/KQwIMLkvHI

    Post summary

    The tweet announces CVE-2026-60002 affecting OpenSSH and directs readers to an external link for additional information.

    01000196
    6.7K followersView on X
  • Reelix@Reelix
    Disclosure

    https://nvd.nist.gov/vuln/detail/CVE-2026-60002 How does a client-side bug (AKA: Requires a client to take an action) have a UI:N (No user interaction required)? Sure, I understand you can automate stuff, but still - That feels like it should be UI:R...

    Post summary

    The post focuses on a CVSS user interaction detail for a client-side vulnerability, providing limited technical context but no PoC, exploit, patch, active exploitation, or debunking claim.

    0000050
    495 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-60002 ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.) https://www.cve.org/CVERecord?id=CVE-2026-60002 ----- Traducción: CVE-2026-60002 ssh en Open… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-60002, a client‑side use‑after‑free flaw in OpenSSH triggered by a host key change during key exchange; no PoC, exploit, active use, patch or debunking claim is present.

    0000053
    91 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-60002 ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.) https://www.cve.org/CVERecord?id=CVE-2026-60002

    Post summary

    The post announces a use‑after‑free vulnerability in OpenSSH clients (pre‑10.4) that occurs during key re‑exchange after a host key change.

    00000703
    57.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenbsdopenssh---

Explore more