OpenSSH Security Updates – 09 July 2026

OpenSSH has released security updates to address several vulnerabilities.

The addressed vulnerabilities could allow the attacker to conduct denial-of-service attacks, obtain sensitive information, manipulate files, or bypass security restrictions on the affected systems.

Sample of the addressed vulnerabilities:

1. OpenSSH Use-After-Free Vulnerability (CVE-2026-60002):

  • CVSS: 7.7
  • Attack Vector: Network
  • Attack Complexity: High
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Denial-of-Service

2. OpenSSH Bypass Authentication Vulnerability (CVE-2026-60001):

  • CVSS: 6.5
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Security Bypas
Vulnerabilities
  • CVE-2026-60002
  • CVE-2026-59995
  • CVE-2026-59996
  • CVE-2026-60001
  • CVE-2026-59999
  • CVE-2026-60000
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

OpenSSH Security Update

References