OpenBSD Makers of OpenBSD operating system, LibreSSL and OpenSSH
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any OpenBSD product.
RSS Feeds for OpenBSD security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in OpenBSD products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by OpenBSD Sorted by Most Security Vulnerabilities since 2018
Known Exploited OpenBSD Vulnerabilities
The following OpenBSD vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| OpenSMTPD Remote Code Execution Vulnerability |
smtp_mailaddr in smtp_session.c in OpenSMTPD, as used in OpenBSD and other products, allows remote attackers to execute arbitrary commands as root via a crafted SMTP session. CVE-2020-7247 Exploit Probability: 99.0% |
March 25, 2022 |
The vulnerability CVE-2020-7247: OpenSMTPD Remote Code Execution Vulnerability is in the top 1% of the currently known exploitable vulnerabilities.
By the Year
In 2026 there have been 21 vulnerabilities in OpenBSD with an average score of 4.8 out of ten. Last year, in 2025 OpenBSD had 12 security vulnerabilities published. That is, 9 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.73
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 21 | 4.84 |
| 2025 | 12 | 5.57 |
| 2024 | 14 | 7.95 |
| 2023 | 15 | 6.95 |
| 2022 | 3 | 6.23 |
| 2021 | 6 | 6.14 |
| 2020 | 5 | 7.70 |
| 2019 | 12 | 6.52 |
| 2018 | 6 | 6.16 |
It may take a day or so for new OpenBSD vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent OpenBSD Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-56101 | Sep 08, 2026 |
OpenBSD TKIP MIC Failure Countercheck Inversion: DoS via RFOpenBSD before commit 1ee99df contains an inverted comparison vulnerability in the ieee80211_michael_mic_failure() function within sys/net80211/ieee80211_crypto_tkip.c that allows unauthenticated attackers within RF range to trigger denial of service by sending two malformed TKIP frames separated by more than 60 seconds. Attackers can exploit the reversed TKIP MIC failure countermeasure window check to deauthenticate all associated TKIP stations and block reassociation for up to 90 seconds, while within-window MIC failures that should engage countermeasures are silently discarded, leaving key-recovery attempts undetected. |
|
| CVE-2026-73283 | Aug 11, 2026 |
OpenSSH <10.5: restrict keyword fails to block tunnel forwarding in sshdIn sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not. |
|
| CVE-2026-73282 | Aug 11, 2026 |
OpenSSH <10.5 UAF via Concurrent Remote-Forwarding (CVE-2026-73282)In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent. |
|
| CVE-2026-73281 | Aug 11, 2026 |
SSH-AGENT Performs Remote Ops in OpenSSH <10.5 (session-bind)In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension. |
|
| CVE-2026-60002 | Jul 08, 2026 |
OpenSSH <=10.3 Use-After-Free via Host Key Change (ssh)ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.) |
|
| CVE-2026-60001 | Jul 08, 2026 |
OpenSSH sshd min auth delay bypass before 10.4sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay. |
|
| CVE-2026-60000 | Jul 08, 2026 |
OpenSSH <10.4 GSSAPI MaxAuthTries DoSsshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication. |
|
| CVE-2026-59999 | Jul 08, 2026 |
OpenSSH<10.4 DisableForwarding fails to block PermitTunnelIn sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not. |
|
| CVE-2026-59998 | Jul 08, 2026 |
OpenSSH sshd GSSAPIStrictAcceptorCheck Misconfig Pre-10.4 on ADsshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory. |
|
| CVE-2026-59997 | Jul 08, 2026 |
OpenSSH <=10.3 internal-sftp accepts only first 9 argsinternal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection. |
|