These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A high-severity vulnerability, CVE-2026-60002, was found in OpenSSH before version 10.4. This issue allows for a use-after-free condition when a server changes its host key during a key re-exchange, but only on the client side. The vulnerability has a CVSS score of 7.7 and is considered high severity. The issue arises from a faulty management of memory in the SSH client, which could potentially allow an a [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-08T01:16:29.290Z and has not been modified since then. This vulnerability affects OpenSSH installations prior to version 10.4, potentially allowing for brute-force attacks due to the lack of adherence to the minimum authentication delay. System administrators and security teams should be aware of th [truncated]
CVE-2026-60000 is a low-severity denial of service vulnerability in OpenSSH before 10.4. The vulnerability is caused by mishandling of MaxAuthTries for GSSAPIAuthentication, allowing remote attackers to cause resource consumption from excessive authentication attempts. This issue affects OpenSSH installations prior to version 10.4. System administrators should review their OpenSSH deployments and consider [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-08T01:16:29.010Z and has not been modified since then. This vulnerability affects OpenSSH configurations, specifically the interaction between DisableForwarding and PermitTunnel settings. System administrators should review their configurations and apply patches from OpenSSH as necessary. The CVSS s [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-08T01:16:28.870Z and has not been modified since then. This undocumented security behavior in OpenSSH before 10.4 could potentially impact the security posture of affected systems. Administrators and security teams should review and adjust configurations if necessary.
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-08T01:16:28.727Z and has not been modified since then. OpenSSH users who rely on internal-sftp in sshd should verify their OpenSSH version and consider upgrading to version 10.4 or later to ensure the intended security properties of SFTP connections. The internal-sftp feature in sshd within OpenSSH [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-08T01:16:28.557Z and has not been modified since then. The vulnerability exists in the scp functionality of OpenSSH before version 10.4. When copying files between two remote destinations, there is a possibility that a file could be placed in the parent directory of the intended target directory. Th [truncated]
A MEDIUM severity vulnerability was found in OpenSSH sftp, affecting versions before 10.4. The issue occurs when using the command 'sftp server:/path .' with an attacker-controlled server, allowing improper constraint of downloaded file locations. This vulnerability could potentially lead to unauthorized file downloads and may impact the security of systems using OpenSSH sftp. Administrators and users sho [truncated]
A use-after-free vulnerability was discovered in OpenBSD 7.9, specifically in the sys/kern/sysv_sem.c file. This vulnerability, tracked as CVE-2026-57589, occurs in the sys_semget() function after a context switch using tsleep. Successful exploitation of this bug can lead to local privilege escalation to root. The vulnerability allows an attacker to access memory after it has been freed, which can cause t [truncated]
CVE-2026-56099 is an out-of-bounds read vulnerability in the mpls_do_error function within OpenBSD's sys/netmpls/mpls_input.c. This vulnerability allows remote attackers to disclose kernel stack memory by sending crafted MPLS frames with 16 labels and no Bottom-of-Stack bit set. The vulnerability was patched in OpenBSD commit 6a23123 on June 18, 2026. System administrators and security teams responsible f [truncated]
CVE-2026-55706 is an authentication bypass vulnerability in OpenBSD's PPP implementation. The vulnerability exists in the sppp_pap_input function in sys/net/if_spppsubr.c and allows attackers to bypass authentication via certain zero values for lengths. The OpenBSD project has addressed this issue with a patch. This vulnerability affects OpenBSD systems using PPP for remote access or network connectivity. [truncated]
A low-severity vulnerability was found in OpenSSH before 10.3, allowing command execution via shell metacharacters in a username within a command line. This requires a scenario where the username on the command line is untrusted and a non-default configuration of % in ssh_config. The vulnerability has a CVSS score of 3.6, indicating low severity. System administrators and security teams should be aware of [truncated]
CVE-2026-35385 is a high-severity vulnerability in OpenSSH that allows a file downloaded by scp to be installed setuid or setgid, contrary to user expectations, when the download is performed as root with -O (legacy scp protocol) and without -p (preserve mode). This issue affects OpenSSH versions before 10.3. The vulnerability has a CVSS score of 7.5 and is considered high severity. The CVE was published [truncated]
CVE-2016-6210 is an information-disclosure issue in sshd from OpenSSH before 7.3. In the affected password-authentication path, when SHA256 or SHA512 are used for user password hashing, sshd uses a Blowfish hash of a static password for nonexistent usernames. That creates a measurable timing difference, especially with a large password, which remote attackers can use to enumerate valid usernames.
CVE-2020-7247 is an OpenBSD OpenSMTPD remote code execution vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. Because it is documented as known exploited, organizations running OpenSMTPD should treat it as a patch-now issue and verify that vendor-recommended updates have been applied.
CVE-2016-6244 is a denial-of-service vulnerability in the OpenBSD kernel's sys_thrsigdivert function. According to the published advisory data, a remote attacker can cause a kernel panic by supplying a negative ts.tv_sec value. The NVD entry maps the issue to OpenBSD 5.9 and rates it HIGH with network attack reachability and availability impact only. This is a stability and uptime issue rather than a data [truncated]
CVE-2012-0814 describes an information disclosure issue in OpenSSH sshd where debug messages can reveal authorized_keys command options to authenticated remote users. In environments that rely on shared accounts, forced commands, or restricted shells, that leaked data can cross a privilege boundary because the affected user may not otherwise have legitimate access to the authorized_keys file. The issue is [truncated]