Skip to content
wolfSSH 1.6.0 Addresses Critical SSH Authentication Bypass Vulnerability

wolfSSH 1.6.0 Addresses Critical SSH Authentication Bypass Vulnerability

First seen 8 Oct 2026, 12:33 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 8, 2026 at 13:30 UTC
  • •CVE-2026-16516 is a critical vulnerability allowing SSH authentication bypass.
  • •Affected versions include wolfSSH up to 1.5.0, with a CVSS score of 9.0.
  • •The patch also addresses high and medium severity vulnerabilities in Windows and SSH functionalities.

wolfSSL has released wolfSSH version 1.6.0 to patch five security vulnerabilities, including a critical SSH host-key authentication bypass identified as CVE-2026-16516. This flaw allows a man-in-the-middle attacker to impersonate an SSH server by exploiting insufficient verification of ECDSA host-key authenticity. The vulnerability affects wolfSSH versions up to 1.5.0 and has a CVSS score of 9.0. Additionally, the update addresses a high-severity Windows privilege escalation flaw (CVE-2026-83540) and three medium-severity issues related to Diffie-Hellman key exchange and unauthorized TCP forwarding. The vulnerabilities were disclosed on October 6, 2026, and the patches are now available for affected systems.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2023-12-18
CVE-2023-48795 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-06
wolfSSH 1.6.0 released
wolfSSL released version 1.6.0 to address five vulnerabilities, including a critical SSH authentication bypass.
Gbhackers
2026-10-07
CVE-2026-16516 published
The critical vulnerability CVE-2026-16516 was published, highlighting the SSH host-key authentication bypass issue.
Cybersecuritynews
2026-10-07
CVE-2026-84897 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-07
CVE-2026-81535 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-07
CVE-2026-83742 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-07
CVE-2026-83540 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE

More articles in this cluster (2)

Following this threat?

Track CVE-2023-48795 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions of wolfSSH are affected?
wolfSSH versions up to 1.5.0 are affected by the critical vulnerability.
What is the severity of the vulnerabilities?
The critical vulnerability CVE-2026-16516 has a CVSS score of 9.0, indicating a severe risk.
What should I do if I am using an affected version?
Upgrade to wolfSSH version 1.6.0 immediately to mitigate the vulnerabilities.