CVE-2026-60000: High severity OpenSSH sshd vulnerability
Last updated 13 July 2026
Other sources
sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 9.8p1-9 - Upgrade
Upgrade
debian/opensshto a version that resolves this vulnerability.Fixed in 1:10.4p1-1 - Upgrade
Upgrade
OpenSSH sshdto a version that resolves this vulnerability.Fixed in 10.4 - Configuration
Set MaxAuthTries in sshd_config to limit excessive authentication attempts (DoS via resource consumption due to mishandled MaxAuthTries for GSSAPIAuthentication).
sshd (OpenSSH) MaxAuthTries = reduce to a safe limit (e.g., 3)
Event History
Frequently Asked Questions
What is the severity of CVE-2026-60000?
The severity of CVE-2026-60000 is rated low with a score of 3.7.
How do I fix CVE-2026-60000?
To mitigate CVE-2026-60000, upgrade to OpenSSH version 10.4 or later.
What type of vulnerability is CVE-2026-60000?
CVE-2026-60000 is a denial of service vulnerability affecting the sshd component of OpenSSH.
What are the potential impacts of CVE-2026-60000?
The potential impact of CVE-2026-60000 includes resource consumption leading to service unavailability due to excessive authentication attempts.
Who is affected by CVE-2026-60000?
All users of OpenSSH sshd versions prior to 10.4 are potentially affected by CVE-2026-60000.