Index
Search
Search the public record. Drafts and scheduled notes are not included.
Critical
news
wolfSSH 1.6.0 fixes five security flaws
wolfSSL released wolfSSH 1.6.0 on 6 October 2026 with five CVE fixes: CVE-2026-16516 (Critical, CVSS 4.0 9.0), an ECDSA host key curve check that enables server impersonation by an active MitM against clients with lax host key checks; CVE-2026-83540 (High, 7.7), Windows wolfSSHd logon token reuse across connections; and three Medium issues in key exchange, TCP forwarding and SFTP paths. Not in CISA KEV. No public PoC.
Published 3h ago
CriticalNo PoC
CVE-2026-16516
wolfSSH ECDSA host key curve not validated, enabling server impersonation
Auth bypass
Published 2d ago