EXPOSURES › CVE-2026-60002
CVE-2026-60002
HIGH
DETAIL
SourceNVD · cve
Published2026-07-08
CVSS7.7
Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-60002 ↗
SHAME 25/100
ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)
▸ RECOMMENDED ACTION Patch the affected products and confirm your instances are covered.
PLAYERS IMPLICATED
DESCRIPTION
ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.