CVE-2026-60001: Medium severity OpenSSH sshd vulnerability
Last updated 13 July 2026
Other sources
sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 9.8p1-9 - Upgrade
Upgrade
debian/opensshto a version that resolves this vulnerability.Fixed in 1:10.4p1-1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-60001?
CVE-2026-60001 has a severity rating of medium with a score of 6.5.
What risk does CVE-2026-60001 pose?
CVE-2026-60001 poses a risk level of 40, indicating a moderate level of exploitation potential.
How do I fix CVE-2026-60001?
To fix CVE-2026-60001, upgrade OpenSSH to version 10.4 or later where the vulnerability has been addressed.
What systems are affected by CVE-2026-60001?
CVE-2026-60001 affects OpenSSH sshd prior to version 10.4.
What are the implications of CVE-2026-60001?
The implications of CVE-2026-60001 include a potential bypass of the minimum authentication delay, which can be exploited to facilitate brute-force attacks.