CVE-2026-59998MediumCVSS 4.8

sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.

Published
July 11, 2026
Last Modified
—

🔗 CVE IDs covered (1)

🎯 Affected products3

  • azl3 openssh 9.8p1-10 on Azure Linux 3.0
  • azl3 openssh 9.8p1-8 on Azure Linux 3.0
  • azl3 openssh 9.8p1-9 on Azure Linux 3.0

✅ Remediation

KBRelease Notes (Security Update) Security Update

🔗 References (2)