Skip to content
USN-8721-1: OpenSSH vulnerabilities

USN-8721-1: OpenSSH vulnerabilities

Ubuntu September 3, 2026

It was discovered that OpenSSH's ssh-agent incorrectly handled interactions between agent locking and the [email protected] extension. A remote attacker with access to a forwarded agent connection could possibly use this issue to perform operations that should only be available locally, such as adding tokens or using keys. ( CVE-2026-73281 ) It was discovered that OpenSSH's ssh client incorrectly handled concurrent remote-forwarding operations. A remote attacker could possibly use this issue to cause a use-after-free condition, resulting in a denial of service or the execution of arbitrary code. ( CVE-2026-73282 ) It was discovered that OpenSSH's sshd server incorrectly applied the restrict keyword from authorized_keys to tunnel forwarding requests. A local attacker with an authorized key could possibly use this issue to bypass intended tunnel...

It was discovered that OpenSSH's ssh-agent incorrectly handled interactions between agent locking and the [email protected] extension. A remote attacker with access to a forwarded agent connection could possibly use this issue to perform operations that should only be available locally, such as adding tokens or using keys. ( CVE-2026-73281 )

It was discovered that OpenSSH's ssh client incorrectly handled concurrent remote-forwarding operations. A remote attacker could possibly use this issue to cause a use-after-free condition, resulting in a denial of service or the execution of arbitrary code. ( CVE-2026-73282 )

It was discovered that OpenSSH's sshd server incorrectly applied the restrict keyword from authorized_keys to tunnel forwarding requests. A local attacker with an authorized key could possibly use this issue to bypass intended tunnel...

It was discovered that OpenSSH's ssh-agent incorrectly handled interactions between agent locking and the [email protected] extension. A remote attacker with access to a forwarded agent connection could possibly use this issue to perform operations that should only be available locally, such as adding tokens or using keys. ( CVE-2026-73281 ) It was discovered that OpenSSH's ssh client incorrectly handled concurrent remote-forwarding operations. A remote attacker could possibly use this issue to cause a use-after-free condition, resulting in a denial of service or the execution of arbitrary code. ( CVE-2026-73282 ) It was discovered that OpenSSH's sshd server incorrectly applied the restrict keyword from authorized_keys to tunnel forwarding requests. A local attacker with an authorized key could possibly use this issue to bypass intended tunnel forwarding restrictions. ( CVE-2026-73283 )

It was discovered that OpenSSH's ssh-agent incorrectly handled interactions between agent locking and the [email protected] extension. A remote attacker with access to a forwarded agent connection could possibly use this issue to perform operations that should only be available locally, such as adding tokens or using keys. ( CVE-2026-73281 )

It was discovered that OpenSSH's ssh client incorrectly handled concurrent remote-forwarding operations. A remote attacker could possibly use this issue to cause a use-after-free condition, resulting in a denial of service or the execution of arbitrary code. ( CVE-2026-73282 )

It was discovered that OpenSSH's sshd server incorrectly applied the restrict keyword from authorized_keys to tunnel forwarding requests. A local attacker with an authorized key could possibly use this issue to bypass intended tunnel forwarding restrictions. ( CVE-2026-73283 )

After a standard system update you need to restart OpenSSH to make all the necessary changes.

The problem can be corrected by updating your system to the following package versions:

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.

Extracted Entities

Attack Types (1)

CWE Weaknesses (1)

Domains (1)

Email Addresses (1)

Platforms (1)