A Critical OpenSSH Vulnerability Is Being Patched, Update Now
Administrators should apply the latest patches promptly. Here is what the flaw affects and how to check your exposure.
Sep 29, 2026 · 2 min read
4 articles
Administrators should apply the latest patches promptly. Here is what the flaw affects and how to check your exposure.
Sep 29, 2026 · 2 min read
On July 1, 2024, Qualys disclosed CVE-2024-6387, nicknamed regreSSHion, a signal-handler race condition in OpenSSH's sshd server that on glibc-based Linux could allow unauthenticated remote code execution as root. Here are the confirmed technical facts, affected versions, and remediation.
Jul 1, 2024 · 2 min read
On November 1, 2022, the OpenSSL project released OpenSSL 3.0.7 to fix CVE-2022-3602 and CVE-2022-3786, two buffer overflows in X.509 certificate verification. Pre-announced as critical, they were downgraded to high severity after further analysis. Here are the confirmed facts and remediation.
Nov 1, 2022 · 2 min read
On December 10, 2021, the Apache Log4j vulnerability CVE-2021-44228, nicknamed Log4Shell, was publicly disclosed. The critical, CVSS 10.0 remote-code-execution flaw in Log4j 2's JNDI lookups affected a huge range of Java software. Here are the confirmed facts, affected versions, and remediation.
Dec 10, 2021 · 2 min read