- Qualys uncovers two bugs in OpenSSH
- The flaws could be used in Machine-in-the-Middle and Denial-of-Service attacks
- Patches are available, as well as some mitigations
OpenSSH carried two vulnerabilities that were enabling machine-in-the-middle (MitM) attacks and denial-of-service (DoS) attacks, experts have warned.
Cybersecurity researchers from the Qualys Threat Research Unit (TRU), who discovered the flaws and helped patch things up, noted they spotted two vulnerabilities, one tracked as CVE-2025-26465, and another tracked as CVE-2025-26466.