Skip to content
Critical OpenSSH Vulnerabilities Affecting Multiple Ubuntu Versions

Critical OpenSSH Vulnerabilities Affecting Multiple Ubuntu Versions

First seen 29 Apr 2026, 17:36 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •April 30, 2026 at 17:35 UTC
  • •OpenSSH vulnerabilities could lead to arbitrary code execution and privilege escalation.
  • •Affected Ubuntu versions include 22.04 LTS and derivatives, with critical updates required.
  • •First public PoC for CVE-2026-35414 released today, increasing urgency for patching.

Multiple vulnerabilities in OpenSSH have been discovered, affecting Ubuntu 22.04 LTS and its derivatives. Key issues include improper handling of the legacy scp protocol, which could lead to unintended setuid or setgid file installations (CVE-2026-35385), and vulnerabilities allowing arbitrary code execution via crafted usernames (CVE-2026-35386). Other vulnerabilities involve incorrect parsing of security options (CVE-2026-35387) and proxy-mode multiplexing issues (CVE-2026-35388). The vulnerabilities were published on April 2, 2026, with the first public proof of concept for CVE-2026-35414 released today. Users are advised to update their systems to mitigate these risks. The affected versions include Ubuntu 26.04 LTS, 25.10, 24.04 LTS, and 22.04 LTS, with specific package versions provided for remediation.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 163d ago How this analysis works

Timeline

2026-04-02
CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388 published
2026-04-02
CVE-2026-35414 published
2026-04-29
First public PoC for CVE-2026-35414 released
2026-04-29
Security advisory published for OpenSSH vulnerabilities

More articles in this cluster (3)

Following this threat?

Track Ubuntu and CVE-2026-35385 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed