CVE-2026-55653
A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) cl
CVSS
4.3
Medio
EPSS
0.3%
p22
KEV
—
Exploit Today
7
0-100
Publicado: 23 jun 2026 · Última mod.: 1 sept 2026 · CWE-415
0.3%EPSS · 30 días0.3%
2026-08-112026-09-07
A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mode known-group validation when the client processes attacker-controlled DH-GEX group parameters. Successful exploitation leads to client-side process termination, resulting in a Denial of Service (DoS).
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:36759
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:47755
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:47756
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:47757
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:54387
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:58981
- access.redhat.comhttps://access.redhat.com/security/cve/CVE-2026-55653
- bugzilla.redhat.comhttps://bugzilla.redhat.com/show_bug.cgi?id=2462351
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-799077.8 ALT—
———Acrobat Reader is affected by a Double Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.7hCVE-2026-819507.8 ALT—
———Double free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.9hCVE-2026-800808.8 ALT—
———Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.8hCVE-2026-775048.8 ALT—
———Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.8hCVE-2026-774939.8 CRÍ—
———Double free in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.10hCVE-2026-729588.2 ALT—
———Double free in Windows Credential Guard allows an authorized attacker to elevate privileges locally.10h