AUGUST 25, 2026
Live Feed
Back to database
Case File

CVE-2026-59998

MEDIUM · CVSS 4.8 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-07-08 · Last synced 2026-08-07

CyberRota Analysis

AI-Generated

OpenSSH versions prior to 10.4 on Windows exhibit a security vulnerability where the GSSAPIStrictAcceptorCheck setting is ineffective when the server is part of an Active Directory environment. This could allow unauthorized access or man-in-the-middle attacks due to improper validation of server credentials. Organizations utilizing OpenSSH on Windows within Active Directory should prioritize patching to mitigate potential security risks.

CVE
CVE-2026-59998
Severity
MEDIUM
CVSS
4.8
EPSS
0.18%
Windows

Original NVD Description

sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.

Related CVEs

Other vulnerabilities affecting the same vendor(s)