Microsoft Security Response Center guidance
Vendor revision: Aug 12, 2026CBL-Mariner Releases
Vendor-listed releases
- 26.2.5.11-1
- 25.3.2.20-1
Erlang Erlang/OTP SSH Server Missing Authentication for Critical Function Vulnerability
CISA lists CVE-2025-32433 in its Known Exploited Vulnerabilities catalog, which means exploitation has been observed. The entry applies to Erlang Erlang/OTP.
Public exploit: Cataloged public exploit.
Rapid7 catalogs an exploit module for this CVE. Module availability does not establish exploitation in the wild or applicability to your environment.
CBL-Mariner Releases
Vendor-listed releases
Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE).
By exploiting a flaw in SSH protocol message handling, a malicious actor could gain unauthorized access to affected systems and execute arbitrary commands without valid credentials. This issue is patched in versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20.
A temporary workaround involves disabling the SSH server or to prevent access via firewall rules.
Source: NVD