Openbsd Openssh — CVE-2026-60002 (Critical)

Date Jul 8, 2026
Type Vendor advisory
Signal Critical vendor advisory
Vendor / Product Openbsd · Openssh
CVE CVE-2026-60002
Critical vendor advisory CVE-2026-60002

Summary

ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)

Why it matters

This CVE carries a CRITICAL severity rating (CVSS 7.7) in Openbsd Openssh. Patch or mitigate promptly. EPSS percentile: 16%.

Operator check

Review CVE-2026-60002 in your asset inventory. Apply patches per vendor guidance and verify Openssh is not exposed. CVSS score: 7.7. EPSS probability: 0.3%; percentile: 16%.

Sources

PatchBrief uses public sources. It does not scan environments, verify exposure, or replace vendor guidance.