Gbhackers wolfSSH 1.6.0 Addresses Critical SSH Authentication Bypass Vulnerability
Article Content
- •CVE-2026-16516 is a critical vulnerability allowing SSH authentication bypass.
- •Affected versions include wolfSSH up to 1.5.0, with a CVSS score of 9.0.
- •The patch also addresses high and medium severity vulnerabilities in Windows and SSH functionalities.
wolfSSL has released wolfSSH version 1.6.0 to patch five security vulnerabilities, including a critical SSH host-key authentication bypass identified as CVE-2026-16516. This flaw allows a man-in-the-middle attacker to impersonate an SSH server by exploiting insufficient verification of ECDSA host-key authenticity. The vulnerability affects wolfSSH versions up to 1.5.0 and has a CVSS score of 9.0. Additionally, the update addresses a high-severity Windows privilege escalation flaw (CVE-2026-83540) and three medium-severity issues related to Diffie-Hellman key exchange and unauthorized TCP forwarding. The vulnerabilities were disclosed on October 6, 2026, and the patches are now available for affected systems.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2023-48795 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which versions of wolfSSH are affected?
What is the severity of the vulnerabilities?
What should I do if I am using an affected version?
Continue Reading
Critical Citrix NetScaler Vulnerabilities Actively Exploited in Finland The National Cyber Security Centre Finland (NCSC-FI) issued an alert regarding critical vulnerabilities in Citrix NetScaler ADC and Gateway products, specifically CVE-2026-88771 and CVE-2026-88772, which are being actively exploited in Finland. These vulnerabilities allow attackers to execute remote code without…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…