Critical OpenSSH Vulnerabilities Disclosed in USN-8721-1

Critical OpenSSH Vulnerabilities Disclosed in USN-8721-1

First seen 3 Sep 2026, 17:39 UTC UbuntuLinuxsecurity 57.9

Article Content

Browse articles
ThreatCluster

On September 3, 2026, Ubuntu published USN-8721-1, detailing multiple vulnerabilities in OpenSSH. The vulnerabilities include CVE-2026-73281, where the ssh-agent mishandles agent locking, allowing remote attackers to perform local operations. CVE-2026-73282 involves a use-after-free condition in the ssh client, which could lead to denial of service or arbitrary code execution. CVE-2026-73283 allows local attackers to bypass tunnel forwarding restrictions. All vulnerabilities were published on August 11, 2026, and affect various versions of OpenSSH across multiple Ubuntu LTS releases. Users are advised to update their systems to mitigate these risks. The vulnerabilities pose a significant threat due to their potential for exploitation in active environments.

Key Points: • Three critical vulnerabilities in OpenSSH disclosed, affecting multiple Ubuntu LTS versions. • CVE-2026-73281 allows remote attackers to perform local operations via ssh-agent. • Immediate updates are required to mitigate risks associated with these vulnerabilities.

Timeline

2026-08-11
CVE-2026-73281 published
OpenSSH's ssh-agent vulnerability allows remote attackers to perform local operations.
Ubuntu
2026-08-11
CVE-2026-73282 published
Vulnerability in ssh client could lead to denial of service or arbitrary code execution.
Ubuntu
2026-08-11
CVE-2026-73283 published
Local attackers can bypass tunnel forwarding restrictions due to a flaw in sshd server.
Ubuntu
2026-09-03
USN-8721-1 advisory published
Ubuntu issued an advisory detailing the vulnerabilities and urging users to update OpenSSH.
Linuxsecurity