https://seclists.org/oss-sec/2026/q1/313: OpenSSH GSSAPI keyex patch issue
Published Mar 14, 2026
·Updated
Affected Software
5 affected components
OpenSSH OpenSSH
ubuntu/openssh-server
redhat/openssh<=10
redhat/openssh<6
redhat/openssh<7
Frequently Asked Questions
1
What is the severity of CVE-2026-XXXX?
The severity of CVE-2026-XXXX is currently classified as critical due to its impact on secure key exchanges.
2
How do I fix CVE-2026-XXXX?
To fix CVE-2026-XXXX, you should update to the latest version of OpenSSH provided by your distribution.
3
Which versions of OpenSSH are affected by CVE-2026-XXXX?
CVE-2026-XXXX affects various versions of OpenSSH that include the GSSAPI key exchange patch.
4
Is there a workaround for CVE-2026-XXXX?
A temporary workaround for CVE-2026-XXXX may involve disabling GSSAPI key exchange if an immediate update cannot be applied.
5
When was CVE-2026-XXXX published?
CVE-2026-XXXX was published on March 14, 2026.