logo

Qualys TRU Discovers Two Vulnerabilities in OpenSSH: CVE-2025-26465 & CVE-2025-26466

ID: 91af6481-f16c-5bce-9d55-ab29182bb90a

STIX ID: report--91af6481-f16c-5bce-9d55-ab29182bb90a

Feed Name: Qualys Blog

Threat Score
70/100

Date Published: 2025-02-18

Date Updated: 2026-04-28

Author: Saeed Abbasi

...
...

Qualys TRU disclosed two OpenSSH vulnerabilities—CVE-2025-26465 enabling a client-side MITM when VerifyHostKeyDNS is enabled and CVE-2025-26466 enabling a pre-authentication DoS against client and server—affecting OpenSSH versions 6.8p1 through 9.9p1 and 9.5p1 through 9.9p1 respectively; Qualys recommends upgrading to OpenSSH 9.9p2 and provides QIDs, detection/mitigation guidance, and asset discovery queries for remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.