Overview
What is CVE-2026-60002?
ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)
Vulnerability intelligence
CVE-2026-60002 and is rated Critical severity with a CVSS score of 9.4. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)