CVE-2026-106587EPSS p0.3%

CVE-2026-106587CVE-2026-106587

openbsd / openssh

Description

In sshd in OpenSSH before 10.6, the value "none" for a configuration option is sometimes interpreted as a filename but was intended to mean that a feature is disabled.

Scoring

CVSS 3.6 ()
VectorCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L
EPSS0.08% probability of exploitation · percentile 0.3% · 2026-10-10T12:00:23Z
Last modified2026-10-09
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.