CVE-2026-35388: Low severity Microsoft azl3 openssh 9.8p1-5 vulnerability
Published Apr 2, 2026
·Updated
OpenSSH before 10.3 omits connection multiplexing confirmation for proxy-mode multiplexing sessions.
Affected Software
6 affected componentsFixes available
Microsoft azl3 openssh 9.8p1-5
OpenBSD OpenSSH<10.3
IBM Verify Identity Access<=11.0 - 11.0.2
IBM Security Verify Access<=10.0 - 10.0.9.1
IBM Verify Identity Access Container<=11.0 - 11.0.2
IBM Security Verify Access Container<=10.0 - 10.0.9.1
Event History
Apr 2, 2026
CVE Published
via MITRE·04:57 PM
Data Sourced
via MITRE·04:57 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Data Sourced
via Red Hat·06:02 PM
DescriptionSeverityAffected Software
Apr 4, 2026
Data Sourced
via Microsoft·08:02 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:02 AM
Severity
Jul 8, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-35388?
CVE-2026-35388 is categorized as a medium severity vulnerability.
2
How do I fix CVE-2026-35388?
To fix CVE-2026-35388, you should upgrade to OpenSSH version 10.3 or higher.
3
What products are affected by CVE-2026-35388?
CVE-2026-35388 affects OpenSSH versions prior to 10.3 in proxy-mode multiplexing sessions.
4
What are the implications of CVE-2026-35388?
CVE-2026-35388 can lead to potential security risks due to the omission of connection multiplexing confirmation.
5
Is there a workaround for CVE-2026-35388?
There are no known workarounds for CVE-2026-35388 other than upgrading to the patched version of OpenSSH.