Index
Search
Search the public record. Drafts and scheduled notes are not included.
news
wolfSSH 1.6.0 fixes five security flaws
wolfSSL released wolfSSH 1.6.0 on 6 October 2026 with five CVE fixes: CVE-2026-16516 (Critical, CVSS 4.0 9.0), an ECDSA host key curve check that enables server impersonation by an active MitM against clients with lax host key checks; CVE-2026-83540 (High, 7.7), Windows wolfSSHd logon token reuse across connections; and three Medium issues in key exchange, TCP forwarding and SFTP paths. Not in CISA KEV. No public PoC.
Published 3h ago
CVE-2026-16516
wolfSSH ECDSA host key curve not validated, enabling server impersonation
Auth bypass
Published 2d ago
CVE-2026-81535
wolfSSH admits forwarded-tcpip channels without authorization check
Other
Published 2d ago
CVE-2026-83540
wolfSSHd on Windows reuses logon token across connections
Auth bypass
Published 2d ago
CVE-2026-83742
wolfSSH SFTP path handling off-by-one NUL write on non-Windows
DoS
Published 2d ago
CVE-2026-84897
wolfSSH server accepts server-only DH group exchange messages from clients
DoS
Published 2d ago