CVE-2026-60002
published 2026-07-08CVE-2026-60002: ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)
PriorityP352critical9.4CVSS 3.1
AVNACLPRNUINSUCHIHAL
EPSS
0.30%
22.3th percentile
ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| openbsd | openssh | < 10.4 | 10.4 |
| openbsd | openssh | — | — |
| ubuntu | openssh | — | — |
CVSS provenance
nvdv3.19.4CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
vendor_redhat7.7HIGH
vendor_ubuntu5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
OpenBSD OpenSSH up to 10.3 use after free
vuldb·2026-07-08·CVSS 7.7
CVE-2026-60002 [HIGH] OpenBSD OpenSSH up to 10.3 use after free
A vulnerability was found in OpenBSD OpenSSH up to 10.3. It has been rated as critical. Affected by this vulnerability is an unknown functionality. Performing a manipulation results in use after free.
This vulnerability is identified as CVE-2026-60002. The attack can be initiated remotely. There is not any exploit available.
GHSA
ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange.
ghsa_unreviewed·2026-07-08
CVE-2026-60002 [HIGH] CWE-416 ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange.
ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)
Ubuntu
OpenSSH vulnerabilities
vendor_ubuntu·2026-07-13·CVSS 5.4
CVE-2026-60001 [MEDIUM] OpenSSH vulnerabilities
Title: OpenSSH vulnerabilities
Summary: Several security issues were fixed in OpenSSH.
It was discovered that OpenSSH sftp did not properly constrain the location
of downloaded files when connecting to an attacker-controlled server. An
attacker could possibly use this issue to write files to unintended
locations on the file system. (CVE-2026-59995)
It was discovered that OpenSSH scp could place files in the parent
directory of the intended destination when copying between two remote
hosts. An attacker could possibly use this issue to write files to
unintended locations. (CVE-2026-59996)
It was discovered that OpenSSH internal-sftp only recognized the first nine
command-line arguments, This could result in certain security-sensitive
arguments being ignored, contrary to expectations. (CV
Red Hat
openssh: OpenSSH: Use-after-free vulnerability during host key re-exchange on the client side
vendor_redhat·2026-07-08·CVSS 7.7
CVE-2026-60002 [HIGH] CWE-825 openssh: OpenSSH: Use-after-free vulnerability during host key re-exchange on the client side
openssh: OpenSSH: Use-after-free vulnerability during host key re-exchange on the client side
A flaw was found in OpenSSH. A remote attacker could exploit a use-after-free vulnerability on the client side when a server changes its host key during a key re-exchange. This could lead to high impact on confidentiality and integrity, and low impact on availability.
Statement: This Important flaw in OpenSSH client could allow a malicious SSH server to execute arbitrary code on the connecting client due to a use-after-free vulnerability during host key re-exchange. While requiring a connection to a specially crafted server, the potential for high impact on client confidentiality and integrity elevates the severity beyond Moderate.
Mitigation: To mitigate this issue, OpenSSH clients should only
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-60002 openssh: OpenSSH: Use-after-free vulnerability during host key re-exchange on the client side [fedora-all]
bugzilla·2026-07-08·CVSS 7.7
CVE-2026-60002 [HIGH] CVE-2026-60002 openssh: OpenSSH: Use-after-free vulnerability during host key re-exchange on the client side [fedora-all]
CVE-2026-60002 openssh: OpenSSH: Use-after-free vulnerability during host key re-exchange on the client side [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)
Bugzilla
CVE-2026-60002 openssh: OpenSSH: Use-after-free vulnerability during host key re-exchange on the client side
bugzilla·2026-07-08·CVSS 7.7
CVE-2026-60002 [HIGH] CVE-2026-60002 openssh: OpenSSH: Use-after-free vulnerability during host key re-exchange on the client side
CVE-2026-60002 openssh: OpenSSH: Use-after-free vulnerability during host key re-exchange on the client side
ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)
2026-07-08
Published