OpenSSH released security updates to address two vulnerabilities tracked as CVE-2025-26465 and CVE-2025-26466, with downstream advisories warning that affected deployments could face both server impersonation and service disruption. According to vendor and researcher disclosures, CVE-2025-26465 can enable a man-in-the-middle attack when VerifyHostKeyDNS is enabled, allowing an attacker to bypass host verification, present a crafted key, impersonate a trusted SSH server, and potentially intercept sessions, access sensitive data, or execute commands.
The second issue, CVE-2025-26466, is a pre-authentication denial-of-service flaw caused by unbounded memory allocation triggered through SSH2_MSG_PING messages, which can exhaust memory and disrupt SSH availability. Guidance from OpenSSH and national CSIRT reporting urges organizations to upgrade to OpenSSH 9.9p2 or later, disable VerifyHostKeyDNS unless it is strictly required, and harden exposed services with connection controls such as LoginGraceTime, MaxStartups, and PerSourcePenalties to reduce exploitation risk.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
CSIRT.SK published an advisory describing the impact of CVE-2025-26465 and CVE-2025-26466 and recommending upgrades to OpenSSH 9.9p2 or later. The notice also advised disabling VerifyHostKeyDNS unless necessary and enforcing connection limits such as LoginGraceTime and MaxStartups.
Qualys reported that CVE-2025-26466 was introduced in OpenSSH 9.5p1 via support for the SSH2_MSG_PING packet, enabling a pre-authentication denial-of-service condition through asymmetric resource consumption and memory exhaustion.
Qualys reported that CVE-2025-26465 was introduced in OpenSSH 6.8p1 when a code change caused the client to accept a server key if the VerifyHostKeyDNS option was enabled, exposing affected clients to machine-in-the-middle attacks.
OpenSSH developers released version 9.9p2 to fix CVE-2025-26465 and CVE-2025-26466. The update addressed the VerifyHostKeyDNS-related host verification issue and the SSH2_MSG_PING memory exhaustion flaw.
Qualys Threat Research Unit discovered CVE-2025-26465 and CVE-2025-26466 in OpenSSH and coordinated disclosure with the OpenSSH developers. The flaws enabled a machine-in-the-middle attack in certain client configurations and a pre-authentication denial-of-service attack against servers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.