A critical flaw in OpenSSH server, tracked as CVE-2024-6387 and dubbed regreSSHion, can allow an unauthenticated attacker to achieve remote code execution with root privileges under specific conditions. The issue affects OpenSSH versions 8.5p1 through 9.7p1, and public reporting says it has been actively exploited in the wild with proof-of-concept code available. Researchers and national defenders also highlighted related issues, including CVE-2024-6409, a less severe code-execution variant identified during analysis, and CVE-2024-7589, a FreeBSD-specific variant patched separately.
Defenders were urged to upgrade to OpenSSH 9.8p1 or later to remove exposure. Where immediate patching is not possible, guidance recommends temporarily restricting or disabling SSH access, or setting LoginGraceTime to 0 as a mitigation, while warning that this workaround can disrupt service availability and should be treated as temporary until systems are fully updated.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
The references state that administrators should upgrade to OpenSSH 9.8p1 or later to remediate CVE-2024-6387, indicating that version 9.8p1 was released with a fix for the issue.
On August 13, 2024, CSIRT.SK published an alert stating that CVE-2024-6387 was being actively exploited in the wild and that public proof-of-concept code was available.
The CSIRT.SK reference says a FreeBSD-specific variant, CVE-2024-7589, was identified and patched separately by FreeBSD developers.
During analysis of CVE-2024-6387, researchers identified a related but less severe code-execution issue, tracked as CVE-2024-6409.
On July 1, 2024, Qualys publicly disclosed CVE-2024-6387 ("regreSSHion"), describing it as a remote unauthenticated code execution vulnerability affecting OpenSSH servers from 8.5p1 through 9.7p1.
Qualys reported that a regression introduced in October 2020 (OpenSSH 8.5p1) reintroduced a previously fixed signal-handler vulnerability, later tracked as CVE-2024-6387 or "regreSSHion." The flaw can enable unauthenticated remote code execution as root under specific conditions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.