Linuxsecurity Critical Vulnerabilities in Fedora's python-asyncssh Affect Multiple Versions
Article Content
- •CVE-2026-54590 allows unauthorized file modification via directory escape.
- •CVE-2026-54591 enables arbitrary file writes through path traversal in SCP client.
- •Users must upgrade to python-asyncssh version 2.24.0 to mitigate these vulnerabilities.
Fedora has released updates for python-asyncssh to address two critical vulnerabilities, CVE-2026-54590 and CVE-2026-54591, which allow unauthorized file modifications and arbitrary file writes through path traversal. These vulnerabilities affect versions 2.22.0 and earlier, with the latest patched version being 2.24.0. The vulnerabilities were published on July 8, 2026, and have been confirmed to impact systems using the authorized-keys directory escape method. Users are urged to update their systems to mitigate potential exploitation. The updates were made available through the 'dnf' package manager. The vulnerabilities could lead to significant security risks if left unaddressed, particularly in environments relying on SSH for secure communications.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Fedora and CVE-2026-54590 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…