USN-8804-1: OpenSSH vulnerabilities
Ubuntu patched two OpenSSH flaws, including command execution on 14.04 and an ECDSA bypass.
Ubuntu Security Notice USN-8804-1 covers two OpenSSH vulnerabilities. CVE-2026-35386 involves incorrect handling of shell metacharacters in certain usernames, which could allow arbitrary command execution, but only on Ubuntu 14.04 LTS and only with certain non-default configurations. CVE-2026-35387 involves incorrect ECDSA algorithm restrictions that could let unintended ECDSA algorithms be accepted and bypass security restrictions. The notice does not report active exploitation.