Critical OpenSSH Vulnerability Affects Ubuntu 16.04 LTS

Critical OpenSSH Vulnerability Affects Ubuntu 16.04 LTS

First seen 22 Jul 2026, 02:53 UTC UbuntuLinuxsecuritylaunchpad.net 84% similarity 57.9

Article Content

Browse articles
ThreatCluster

A vulnerability in OpenSSH (CVE-2026-35414) was discovered by Vladimir Tokarev, affecting Ubuntu 16.04 LTS. The flaw arises from improper handling of certificates with principal names containing commas, which can lead to unintended access to network services. This issue was addressed in the Ubuntu Security Notice USN-8577-1, which provides a fix corresponding to USN-8222-1. Users are advised to update their systems to mitigate potential security risks. The vulnerability was published on April 2, 2026, with the first public proof of concept released on April 29, 2026. The scope of impact is significant as it could allow unauthorized access to services if exploited. Ubuntu Pro users can benefit from extended security coverage for affected packages.

Key Points: • CVE-2026-35414 affects OpenSSH on Ubuntu 16.04 LTS, allowing unintended access. • The vulnerability was discovered by Vladimir Tokarev and reported in April 2026. • Users are advised to update their systems to the latest package versions to mitigate risks.

ThreatCluster AI

Timeline

2026-04-02
CVE-2026-35414 published
A vulnerability in OpenSSH was disclosed, affecting its handling of certificates with commas.
Ubuntu
2026-04-29
First public PoC released
The first proof of concept for exploiting CVE-2026-35414 was made public, raising concerns about its exploitation.
Linuxsecurity
2026-07-21
Ubuntu Security Notice USN-8577-1 issued
Ubuntu released a security notice addressing the OpenSSH vulnerability, urging users to update their systems.
Ubuntu

Community

Browse all →