CVE-2026-59998: Medium severity OpenSSH sshd vulnerability
Last updated 13 July 2026
Other sources
sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/opensshto a version that resolves this vulnerability.Fixed in 1:10.4p1-1 - Upgrade
Upgrade
OpenSSH (sshd)to a version that resolves this vulnerability.Fixed in 10.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-59998?
CVE-2026-59998 has a medium severity rating of 4.8.
What is the risk associated with CVE-2026-59998?
The risk level for CVE-2026-59998 is classified as 32.
How do I mitigate CVE-2026-59998?
To mitigate CVE-2026-59998, upgrade to OpenSSH version 10.4 or later.
What vulnerable software is affected by CVE-2026-59998?
CVE-2026-59998 affects the sshd component of OpenSSH versions before 10.4.
What is the main issue with CVE-2026-59998?
CVE-2026-59998 involves an undocumented behavior in sshd where GSSAPIStrictAcceptorCheck has no value when the server is part of Windows Active Directory.