Skip to content
Threat Feed

Tag

Ssh

23 briefs RSS
medium advisory

SSH Authorized Key File Activity Detected in Containers

Adversaries may modify the Secure Shell (SSH) authorized_keys file inside Linux containers to maintain persistence, achieve lateral movement, or escalate privileges by adding their own public keys, with this activity detected by Elastic Defend for Containers.

container linux persistence lateral-movement privilege-escalation ssh
1r 4t
high advisory

Improper Signature Verification in Lenze Products (CVE-2026-14837)

A low-privileged local attacker can exploit CVE-2026-14837, an improper signature verification vulnerability, in multiple Lenze products including models c430, c520, c550, i950 GenA, and i950 GenB to bypass the verification of the SSH enable file signature, subsequently enabling SSH access on the affected device, resulting in unauthorized administrative access and complete system compromise.

c430 +4 vulnerability ics ot industrial-control-system ssh signature-bypass
2t 1c
high advisory

CVE-2026-66032 - libssh2 SFTP Double-Free Vulnerability

A double-free vulnerability, CVE-2026-66032, in libssh2 versions through 1.11.1 allows a malicious SSH server to corrupt the heap of an authenticated client opening an SFTP session, potentially leading to arbitrary code execution.

libssh2 <= 1.11.1 ssh sftp double-free vulnerability libssh2 memory-corruption rce DoS +2
4t 4c
high advisory

Gitea LFS Authentication Bypass via Malformed SSH Sub-Verb

A high-severity authentication bypass vulnerability (CVE-2026-58423) in Gitea's SSH Git LFS handling allows any authenticated SSH user to obtain valid LFS credentials for any private repository, enabling unauthorized download of all LFS objects from instances running Gitea versions 1.23.0 through 1.26.2.

Gitea lfs ssh authentication-bypass information-disclosure vulnerability
1r 4t 1c
medium advisory

CVE-2026-59999: OpenSSH sshd Configuration Bypass via PermitTunnel

A logic error in OpenSSH's sshd daemon before version 10.4 allowed the PermitTunnel configuration to take precedence over DisableForwarding=yes, leading to unintended SSH tunnel establishment and potential unauthorized network access through the tunnel feature.

OpenSSH ssh vulnerability configuration-bypass linux macos
1c
medium advisory

OpenSSH sshd Denial-of-Service via GSSAPI Authentication (CVE-2026-60000)

A high-severity denial-of-service vulnerability, CVE-2026-60000, affects OpenSSH versions prior to 10.4, allowing remote attackers to exhaust server resources through excessive and mishandled GSSAPI authentication attempts, leading to service unavailability.

OpenSSH < 10.4 +1 denial-of-service ssh openssh network-attack
1c
high advisory

Coder SSH Config Injection Vulnerability (CVE-2026-55427)

A malicious or compromised Coder server can exploit CVE-2026-55427 to inject unsanitized SSH configuration values via `coder config-ssh` into developer workstations, enabling arbitrary code execution on client machines.

Coder +3 ssh configuration-injection rce supply-chain developer-tools vulnerability
1t
critical threat

golang.org/x/crypto/ssh FIDO/U2F Physical Presence Bypass (CVE-2026-39831)

A critical vulnerability (CVE-2026-39831) in the `Verify()` method of the `golang.org/x/crypto/ssh` package (versions prior to 0.52.0) allowed the physical presence check for FIDO/U2F security key types to be bypassed, enabling unattended use of hardware security keys and potentially leading to unauthorized SSH access.

exploited golang.org/x/crypto/ssh ssh vulnerability golang fido u2f
1c
medium advisory

libssh2 Vulnerability: Denial of Service and Information Disclosure

A vulnerability in the libssh2 library allows a remote, unauthenticated attacker to perform a Denial of Service (DoS) attack or disclose sensitive information, potentially leading to service disruption or unauthorized data exposure.

libssh2 ssh vulnerability dos information-disclosure library
3r 2t
high advisory

CVE-2026-39832: Agent Constraints Dropped When Forwarding Keys in golang.org/x/crypto/ssh/agent

CVE-2026-39832 describes a vulnerability where agent constraints are dropped when forwarding keys in golang.org/x/crypto/ssh/agent, potentially leading to unauthorized access.

cve-2026-39832 ssh key forwarding vulnerability
2r 1c
high advisory

Russh CryptoVec Unchecked Allocation Vulnerability

Russh versions up to 0.60.2 are vulnerable to a memory-safety hardening issue due to unchecked `CryptoVec` allocation and growth handling, reachable from local agent inputs and remote SSH traffic, potentially triggering a process abort under constrained memory conditions.

russh +1 memory-allocation denial-of-service ssh CVE-2026-46673
2r
high advisory

goshs SSH Tunnel Vulnerable to MITM via Insecure Host Key Handling

The goshs application disables SSH host key verification when using the --tunnel flag, making it vulnerable to man-in-the-middle attacks that expose plaintext HTTP traffic.

goshs/v2 <= 2.0.6 mitm ssh insecure-configuration
2r 6t
high advisory

Fortra GoAnywhere MFT SSH Key Brute-Force Vulnerability (CVE-2025-14362)

Fortra's GoAnywhere MFT prior to 7.10.0 is vulnerable to brute-force attacks on SSH keys because the login limit is not enforced on the SFTP service when Web Users are configured to log in with an SSH Key.

goanywhere mft bruteforce ssh
2r 1t 1c
critical advisory

UniFi Play Improper Access Control Allows SSH Enablement

CVE-2026-22564 is an improper access control vulnerability in UniFi Play PowerAmp and Audio Port devices that allows an attacker with network access to enable SSH and make unauthorized system changes.

cve-2026-22564 unifi-play access-control ssh
2r 1t 1c
medium advisory

SSH Authorized Key File Modification Inside a Container

The rule detects the creation or modification of an authorized_keys file inside a container, a technique used by adversaries to maintain persistence on a victim host by adding their own public key(s) to enable unauthorized SSH access for lateral movement or privilege escalation.

container persistence lateral-movement privilege-escalation ssh
2r 4t
medium advisory

GitHub SSH Certificate Configuration Changed

Attackers can modify SSH certificate configurations in GitHub organizations to gain unauthorized access, persist in the environment, escalate privileges, and operate stealthily.

Github ssh certificate initial-access persistence privilege-escalation stealth t1078.004
2r 4t
high advisory

OpenCanary SSH Connection Attempt

An SSH connection attempt to an OpenCanary node indicates a potential adversary probing for vulnerable services or attempting unauthorized access within a network.

OpenCanary honeypot ssh reconnaissance
2r 1t
medium advisory

AWS EC2 Instance Connect SSH Public Key Upload

This rule detects the uploading of new SSH public keys to AWS EC2 instances using the EC2 Instance Connect service, which could indicate an adversary attempting to maintain access, escalate privileges, or move laterally within the cloud environment.

EC2 +1 cloud aws ssh lateral-movement privilege-escalation persistence
2r 3t
high advisory

OpenCanary SSH Login Attempt Detection

Detects instances where an SSH service on an OpenCanary node has had a login attempt, indicating potential reconnaissance, privilege escalation, or lateral movement.

OpenCanary honeypot ssh initial-access
2r 1t
high advisory

Potential Remote Desktop Tunneling Detected via SSH

Detection of SSH utilities establishing RDP tunnels, potentially enabling attackers to route network packets to otherwise unreachable destinations, facilitating command and control or lateral movement.

Windows rdp ssh tunneling command-and-control lateral-movement
2r 2t
high advisory

Linux SSH Persistence via Backdoored System User

Attackers can maintain unauthorized access to Linux systems by backdooring system user accounts with SSH keys, allowing persistent access even after password changes.

Linux +1 persistence ssh
3r 2t
medium advisory

ESXi SSH Enabled Detection

The enabling of SSH on ESXi hosts, as detected in ESXi Syslog, can signal malicious lateral movement by threat actors aiming for persistent access.

ESXi ssh lateral-movement
2r 1t
high advisory

ESXi SSH Brute-Force Attack Attempt

Detection of a potential brute-force attack against an ESXi host via SSH by monitoring for a high number of failed login attempts within a short time frame, indicating an attacker attempting to gain unauthorized access.

ESXi ssh brute-force credential-access vmware
2r 1t