Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-26465

33
FAUCET Score

CVE-2025-26465 is a medium-severity vulnerability in OpenSSH, affecting products like Debian, NetApp, OpenBSD, and Red Hat, that allows a machine-in-the-middle (MiTM) attack when the VerifyHostKeyDNS option is enabled. This flaw, stemming from mishandled error codes during host key verification, has a CVSS score of 6.8 and requires an attacker to exhaust client memory, making its attack complexity high. Despite the high complexity, a successful MiTM could lead to high confidentiality and integrity impacts. While not currently listed on the CISA KEV catalog, it is on the Hot List, indicating active monitoring. There is no public exploit code available, but the vulnerability has garnered significant community discussion and media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 6.9, <= 9.8CPE matchmatch criteria
cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:*
6.8CPE matchmatch criteria
cpe:2.3:a:openbsd:openssh:6.8:p1:*:*:*:*:*:*
9.9CPE matchmatch criteria
cpe:2.3:a:openbsd:openssh:9.9:-:*:*:*:*:*:*
9.9CPE matchmatch criteria
cpe:2.3:a:openbsd:openssh:9.9:p1:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*

CVSS Data

CVSS version used by this source: 3.1

6.8MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
1.6
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
7.45%
Probability of exploitation in next 30 days
EPSS Percentile
93.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0745 is in the 95th percentile among its peer group of 707 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (19)

codesyspatch availablevia llm_extracted
View patch
esphomepatch availablevia llm_extracted
View patch
latchsetpatch availablevia llm_extracted
Fixed in: 9.9p2
View patch
microsoftpatch availablevia msrc
Product: cbl2 openssh 8.9p1-8 on CBL Mariner 2.0Fixed in: 8.9p1-7
microsoftpatch availablevia msrc
Product: 19453-17084Fixed in: 9.8p1-3
microsoftpatch availablevia msrc
Product: 19370-17084Fixed in: 9.8p1-3
microsoftpatch availablevia msrc
Product: 19369-16823Fixed in: 8.9p1-7
microsoftpatch availablevia msrc
Product: 20199-17086Fixed in: 8.9p1-7
microsoftpatch availablevia msrc
Product: azl3 openssh 9.8p1-4 on Azure Linux 3.0Fixed in: 9.8p1-3
microsoftpatch availablevia msrc
Product: azl3 openssh 9.8p1-3 on Azure Linux 3.0Fixed in: 9.8p1-3
microsoftpatch availablevia msrc
Product: cbl2 openssh 8.9p1-7 on CBL Mariner 2.0Fixed in: 8.9p1-7
nodejspatch availablevia llm_extracted
Fixed in: 9.9p2
View patch
openldappatch availablevia llm_extracted
Fixed in: 9.9p2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: openssh-0:8.0p1-26.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: openssh-0:8.7p1-45.el9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Discovery 1.14Fixed in: discovery/discovery-server-rhel9:sha256:ad1045aa0de937c3a6969ec377f7bfeda9a44ee434a954e8245e9840316ffc1c
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.4 Extended Update SupportFixed in: openssh-0:8.7p1-38.el9_4.5
View patch
traefikpatch availablevia llm_extracted
Fixed in: 9.9p2
View patch
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: rhcos

Vendor Advisories (8)

esphomellm-esphome-ed450ce9fd6a7380CRITICAL

HP ThinPro 8.1 SP7 Security Updates

Jun 3, 2025
codesysllm-codesys-fe85e88fbae25bb9CRITICAL

HP ThinPro 8.1 SP7 Security Updates

Jun 3, 2025
traefikllm-traefik-035b3c99ce2c1f37

VerifyHostKeyDNS server impersonation

Feb 18, 2025
latchsetllm-latchset-74dc05f41ac3659a

VerifyHostKeyDNS server impersonation.

Feb 18, 2025
openldapllm-openldap-284e6528661c6205

VerifyHostKeyDNS server impersonation.

Feb 18, 2025
nodejsllm-nodejs-e64bf2e4022f125c

VerifyHostKeyDNS server impersonation.

Feb 18, 2025
redhatCVE-2025-26465Moderate

openssh: Machine-in-the-middle attack if VerifyHostKeyDNS is enabled

Feb 17, 2025
microsoft2025-Feb/CVE-2025-26465Moderate

Openssh: machine-in-the-middle attack if verifyhostkeydns is enabled

Feb 11, 2025

References

cert-portal.siemens.com / productcert/html/ssa-082556.html
cert-portal.siemens.com / productcert/html/ssa-585531.html
blog.qualys.com / vulnerabilities-threat-research/2025/02/18/qualys-tru-discovers-two-vulnerabilities-in-openssh-cve-2025-26465-cve-2025-26466
Third Party Advisory
bugzilla.suse.com / show_bug.cgi
Issue Tracking
seclists.org / fulldisclosure/2025/Feb/18
seclists.org / fulldisclosure/2025/May/7
seclists.org / fulldisclosure/2025/May/8
ftp.openbsd.org / pub/OpenBSD/patches/7.6/common/008_ssh.patch.sig
Patch
lists.debian.org / debian-lts-announce/2025/02/msg00020.html
Third Party Advisory
lists.mindrot.org / pipermail/openssh-unix-announce/2025-February/000161.html
Third Party Advisory
security.netapp.com / advisory/ntap-20250228-0003
Third Party Advisory
security-tracker.debian.org / tracker/CVE-2025-26465
Third Party Advisory
ubuntu.com / security/CVE-2025-26465
Third Party Advisory
openssh.com / releasenotes.html
Release Notes
openwall.com / lists/oss-security/2025/02/18/1
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2025/02/18/4
Mailing ListThird Party Advisory
theregister.com / 2025/02/18/openssh_vulnerabilities_mitm_dos
Press/Media Coverage
vicarius.io / vsociety/posts/cve-2025-26465-detect-vulnerable-openssh
Third Party Advisory
vicarius.io / vsociety/posts/cve-2025-26465-mitigate-vulnerable-openssh
MitigationThird Party Advisory
access.redhat.com / errata/RHSA-2025:16823
access.redhat.com / errata/RHSA-2025:3837
access.redhat.com / errata/RHSA-2025:6993
access.redhat.com / errata/RHSA-2025:8385
access.redhat.com / security/cve/CVE-2025-26465
Third Party Advisory
access.redhat.com / solutions/7109879
bugzilla.redhat.com / show_bug.cgi
Issue TrackingThird Party Advisory
seclists.org / oss-sec/2025/q1/144
Mailing ListThird Party Advisory