CVE-2026-35385 affects OpenSSH scp before version 10.3. When scp is used in legacy protocol mode with the -O option, a file downloaded as root without the -p preserve-mode option may be installed with setuid or setgid permission bits intact. This behavior is contrary to expected safe handling of received file modes and stems from scp failing to clear privileged mode bits on received files under this specific code path. The issue is also noted as inherited from longstanding rcp-era behavior and was corrected by clearing setuid and setgid bits on received files.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No valid public exploits. Mallory filtered out 1 candidate as fakes, detection scripts, or README-only repos.
All candidate exploits were filtered out by Mallory's validation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A security vulnerability addressed by backported Dropbear upstream fixes; no further details are provided in the content.
A Dropbear vulnerability fixed by backporting security fixes from Dropbear 2026.90.
An OpenSSH vulnerability affecting scp behavior around setuid and setgid bits, fixed in Debian 13.5.
Уязвимость в реализации scp в Dropbear, связанная с небезопасной обработкой файлов и атрибутов при определённых режимах/опциях, что могло приводить к опасному созданию файлов с повышающими риск правами.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.