Junglewise Threat Intelligence

CVE-2026-60002: OpenSSH use-after-free in ssh client during key re-exchange

CVE-2026-60002 · Severity: high · CVSS 7.7 · Published 2026-07-08

Technologies: OpenBSD Openssh. Vendors: OpenBSD.

Executive brief

OpenSSH is a widely used tool for secure remote access and file transfers. A vulnerability in the client software could allow a malicious server to trigger a memory error when updating security keys during an active session. If successfully exploited, this could allow an attacker to compromise the client machine or cause the connection to crash.

Technical details

A use-after-free vulnerability exists in the OpenSSH client (ssh) prior to version 10.4. The flaw is triggered during a post-authentication key re-exchange if the server changes its host key. An attacker controlling a malicious server can exploit this memory corruption issue to potentially achieve remote code execution or cause a denial of service on the client side. The attack requires a network connection but is mitigated by the high complexity of successfully manipulating memory during the re-exchange process. The issue is resolved in OpenSSH version 10.4.

Affected products

  • OpenBSD OpenSSH before 10.4

Timeline

  • 2026-07-06: patched: OpenSSH 10.4 released with security fixes.
  • 2026-07-08: advisory: CVE-2026-60002 published.

References

Related threats