Two critical vulnerabilities, CVE-2025-26465 and CVE-2025-26466, have been identified in OpenSSH, exposing systems to security risks. CVE-2025-26465 allows attackers to exploit the ‘VerifyHostKey’ DNS option for machine-in-the-middle (MitM) attacks, leading to credential theft. CVE-2025-26466, is a pre-authentication DoS vulnerability that enables attackers to overwhelm SSH servers, causing service disruption. Keeping OpenSSH updated and properly configured is critical to mitigating these risks.
