← Back to home
wid-sec-w-2026-0979  ·  Published 2026-04-06  ·  View on BSI CERT-Bund ↗

OpenSSH: Multiple Vulnerabilities

CVSS 7.5 HIGH

Risk Summary

In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome contrary to some users' expectations, if the download is performed as root with -O (legacy scp protocol) and without -p (preserve mode).

Affected Vendors

Microsoft Open Source

Affected Products (3)

Microsoft · Azure Linux azl3
Open Source · OpenSSH <10.3
Open Source · OpenSSH 10.3

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more