CVE-2026-69397
massUse-After-Free RCE in OpenSSH for Windows
CVE-2026-69397 is a use-after-free (CWE-416) vulnerability in the OpenSSH implementation shipped for Windows, assigned by Microsoft. Triggering requires a network-reachable condition plus user interaction and favorable timing (CVSS: AV:N/AC:H/PR:N/UI:R), which is consistent with an attacker having to induce a user or service into an SSH connection under attacker-controlled conditions before the freed memory is reused. A successful exploit allows an unauthorized attacker to execute arbitrary code on the target with the impact scored as high across confidentiality, integrity, and availability. Any Windows system using the bundled OpenSSH components is potentially affected, with the exact affected version ranges not stated in the available data. Exploitation status is currently quiet: no public proof-of-concept is known, the flaw is not in CISA KEV, and EPSS estimates only a 0.6% probability of exploitation within 30 days.
What to do: Track Microsoft's advisory and apply the patched OpenSSH for Windows version as soon as it is released, prioritizing internet-facing Windows servers with the OpenSSH Server optional feature enabled. As interim mitigation, disable or remove the built-in OpenSSH client/server on systems that do not need it, and restrict inbound SSH exposure with firewall rules. Because no public PoC exists yet, verify vendor guidance on whether the flaw lies in the client or server component before tuning which hosts to remediate first.
| Microsoft OpenSSH for Windows (Windows-bundled OpenSSH) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in OpenSSH for Windows allows an unauthorized attacker to execute code over a network.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.