AUGUST 25, 2026
Live Feed
Back to database
Case File

CVE-2026-60000

LOW · CVSS 3.7 EPSS 0.44%

Source: NVD + CISA KEV + EPSS · Published 2026-07-08 · Last synced 2026-08-07

CyberRota Analysis

AI-Generated

OpenSSH versions prior to 10.4 are vulnerable to a denial of service due to improper handling of the MaxAuthTries setting for GSSAPIAuthentication, allowing remote attackers to exhaust server resources through excessive authentication attempts. Organizations using affected versions of OpenSSH should prioritize patching to mitigate potential service disruptions. While the severity is rated low, the risk of resource exhaustion warrants attention, especially for environments relying heavily on SSH for remote access.

CVE
CVE-2026-60000
Severity
LOW
CVSS
3.7
EPSS
0.44%

Original NVD Description

sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication.

Related CVEs

Other vulnerabilities affecting the same vendor(s)