Feeds2.Feedburner OpenSSH 10.4 Released with Critical Security Fixes
Article Content
Browse articles
- •OpenSSH 10.4 includes eight security fixes, crucial for Unix and Linux systems.
- •Two vulnerabilities in sftp could allow malicious servers to manipulate file downloads.
- •System administrators are urged to upgrade to version 10.4 to prevent exploitation.
On July 6, 2026, OpenSSH released version 10.4, addressing eight security vulnerabilities, including significant flaws in sftp that could allow malicious servers to redirect downloads. The vulnerabilities were identified by the Swival Security Scanner, highlighting risks for Unix and Linux system operators. The release also includes bug corrections and new features, such as early post-quantum cryptography support. System administrators are advised to update to this version to mitigate potential exploitation. The vulnerabilities affect core utilities within OpenSSH, which is widely used for secure remote access.
Ask AI about this cluster
Answers cite the sources they use
Updated 96d ago How this analysis works
Timeline
2026-07-06
OpenSSH 10.4 released
Version 10.4 launched with eight security fixes and new features, including post-quantum cryptography support.
Feeds2.Feedburner2026-07-06
Security vulnerabilities disclosed
The release addresses multiple vulnerabilities in core utilities, particularly in sftp, which could be exploited by malicious servers.
CybersecuritynewsMore articles in this cluster (3)
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…