CVE-2026-60001
published 2026-07-08CVE-2026-60001: sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.
PriorityP343medium6.5CVSS 3.1
AVNACLPRNUINSUCNILAL
EPSS
0.29%
21.4th percentile
sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| openbsd | openssh | < 10.4 | 10.4 |
| openbsd | openssh | — | — |
| ubuntu | openssh | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
vendor_redhat6.5MEDIUM
vendor_ubuntu5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.
ghsa_unreviewed·2026-07-08
CVE-2026-60001 [MEDIUM] CWE-770 sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.
sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.
VulDB
OpenBSD OpenSSH up to 10.3 privilege escalation
vuldb·2026-07-08·CVSS 6.5
CVE-2026-60001 [MEDIUM] OpenBSD OpenSSH up to 10.3 privilege escalation
A vulnerability was found in OpenBSD OpenSSH up to 10.3. It has been declared as problematic. Affected is an unknown function. Such manipulation leads to privilege escalation.
This vulnerability is referenced as CVE-2026-60001. The attack needs to be initiated within the local network. No exploit is available.
Ubuntu
OpenSSH vulnerabilities
vendor_ubuntu·2026-07-13·CVSS 5.4
CVE-2026-60001 [MEDIUM] OpenSSH vulnerabilities
Title: OpenSSH vulnerabilities
Summary: Several security issues were fixed in OpenSSH.
It was discovered that OpenSSH sftp did not properly constrain the location
of downloaded files when connecting to an attacker-controlled server. An
attacker could possibly use this issue to write files to unintended
locations on the file system. (CVE-2026-59995)
It was discovered that OpenSSH scp could place files in the parent
directory of the intended destination when copying between two remote
hosts. An attacker could possibly use this issue to write files to
unintended locations. (CVE-2026-59996)
It was discovered that OpenSSH internal-sftp only recognized the first nine
command-line arguments, This could result in certain security-sensitive
arguments being ignored, contrary to expectations. (CV
Red Hat
openssh: OpenSSH: Brute-force attacks facilitated due to insufficient authentication delay
vendor_redhat·2026-07-08·CVSS 6.5
CVE-2026-60001 [MEDIUM] CWE-307 openssh: OpenSSH: Brute-force attacks facilitated due to insufficient authentication delay
openssh: OpenSSH: Brute-force attacks facilitated due to insufficient authentication delay
A flaw was found in OpenSSH's SSH daemon (sshd). A remote attacker could exploit this vulnerability by repeatedly attempting authentication. The flaw allows the attacker to bypass the intended minimum authentication delay, which can facilitate brute-force attacks. This makes it easier for an attacker to guess valid credentials, potentially leading to unauthorized access or a denial of service.
Package: openssh (Red Hat Enterprise Linux 10) - Fix deferred
Package: openssh (Red Hat Enterprise Linux 6) - Fix deferred
Package: openssh (Red Hat Enterprise Linux 7) - Fix deferred
Package: openssh (Red Hat Enterprise Linux 8) - Fix deferred
Package: openssh (Red Hat Enterprise Linux 9) - Fix deferred
No detection rules found.
No public exploits indexed.
2026-07-08
Published