Review reviewCritical
CVE-2026-60002
OpenBSD OpenSSH, openssh
ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)
- CVSS
- 9.4
- EPSS
- 0.26% 17.8% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.08