Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Gitea Patches Critical SSH Auth Bypass, SSRF, and 25 Other Flaws
October 8, 2026
Microsoft Teams Phishing Scam Steals Credentials with Fake Login Page
October 8, 2026
Critical PoeLLM Malware Targets AI Infrastructure Via GitHub Poem
October 8, 2026
Home/CyberSecurity News/wolfSSH 1.6.0 Patches Critical MITM Host Key Verification Bypass Vulnerability
CyberSecurity News

wolfSSH 1.6.0 Patches Critical MITM Host Key Verification Bypass Vulnerability

Key Takeaways wolfSSL has released wolfSSH 1.6.0 to address five security vulnerabilities. A critical host key verification bypass (CVE-2026-16516) could enable an attacker to impersonate an SSH...

David kimber
David kimber
October 8, 2026 4 Min Read
2 0

Key Takeaways

  • wolfSSL has released wolfSSH 1.6.0 to address five security vulnerabilities.
  • A critical host key verification bypass (CVE-2026-16516) could enable an attacker to impersonate an SSH server under specific conditions.
  • Other flaws include a Windows privilege escalation, unauthenticated key exchange abuse, unauthorized forwarding channels, and an SFTP memory corruption bug.
  • The most severe vulnerabilities impact wolfSSH versions up to 1.5.0.
  • Immediate upgrade to wolfSSH 1.6.0 is recommended for all affected deployments.

Critical Flaw in wolfSSH Allows Server Impersonation

wolfSSL has issued version 1.6.0 of its wolfSSH library, patching a total of five security vulnerabilities, including a critical host key verification bypass that could allow a malicious actor to impersonate an SSH server. The update, released on October 6, 2026, also resolves issues related to Windows privilege escalation, unauthenticated key exchange abuse, unauthorized forwarding channel creation, and an SFTP memory corruption flaw.

Table Of Content

  • Key Takeaways
  • Critical Flaw in wolfSSH Allows Server Impersonation
  • Deep Dive into CVE-2026-16516: Host Key Verification Bypass
  • High-Severity Privilege Escalation on Windows
  • Unauthenticated Diffie-Hellman Group Exchange Abuse
  • Unauthorized Forwarding Channels and SFTP Memory Corruption
  • What You Should Do

The vulnerabilities range in severity, with one rated as critical, one as high, and three as medium. The most significant of these, tracked as CVE-2026-16516, impacts wolfSSH versions up to and including 1.5.0.

Deep Dive into CVE-2026-16516: Host Key Verification Bypass

The critical flaw, CVE-2026-16516, stems from an inadequate check during the SSH key exchange process. Specifically, the client failed to verify if the ECDSA curve embedded within the server’s host key aligned with the cryptographic algorithm negotiated for the connection. This oversight could be exploited by a man-in-the-middle (MITM) attacker who could substitute the legitimate server’s host key with one using a different curve.

Since the attacker would possess the private key corresponding to the replacement key, the signature verification process could still succeed. However, successful exploitation also hinges on the application utilizing a weak public-key-checking callback function. It is important to note that this vulnerability does not inherently mean every affected client will automatically accept an attacker’s key. wolfSSL has credited security researcher zhangph, known by the GitHub handle afldl, for discovering and reporting this critical issue.

High-Severity Privilege Escalation on Windows

A high-severity vulnerability, CVE-2026-83540, affects wolfSSHd on Windows systems running versions 1.4.15 through 1.5.0. This flaw arises from concurrent connections sharing an authentication context that contains a Windows logon token. Both password and public key authentication methods wrote to this shared token, creating a risk that a legitimate user could inadvertently inherit the login identity of another user, potentially one with elevated privileges. Non-Windows builds of wolfSSH are not affected by this particular vulnerability.

Unauthenticated Diffie-Hellman Group Exchange Abuse

CVE-2026-84897 addresses an improper handling of Diffie-Hellman group exchange messages. Vulnerable servers could accept messages intended solely for a server, allowing an unauthenticated client to trigger client-side processing. An attacker, after selecting the diffie-hellman-group-exchange-sha256 method, could submit a custom group and force the server to perform computationally intensive primality checks on its numbers.

The release notes describe this as roughly half a second of CPU work for every 1 KB packet containing a 4096-bit prime. This message-handling flaw impacts versions 1.2.0 through 1.5.0, while the expensive prime checks specifically apply to versions from 1.5.0 onwards. Builds of wolfSSH that utilize the WOLFSSH_NO_DH_GEX_SHA256 option are immune to this issue.

Unauthorized Forwarding Channels and SFTP Memory Corruption

CVE-2026-81535 affects wolfSSH versions 1.4.8 through 1.5.0 built with the --enable-fwd option. The software in these versions accepted forwarded-tcpip channel requests without properly validating them against the application’s configured forwarding policy. Furthermore, clients would accept channels for remote forwards they had not initiated. This could allow a peer to compel an endpoint to allocate buffers for forwarding channels that the application had not explicitly approved, potentially leading to resource exhaustion or other issues.

The fifth vulnerability, CVE-2026-83742, impacts non-Windows builds of wolfSSH from versions 1.4.11 through 1.5.0. This flaw involves incorrect length calculations within the wolfSSH_RealPath() function, which could result in a specially crafted SFTP path writing a null-terminating byte just beyond a stack buffer. An authenticated attacker could leverage this to corrupt adjacent data, potentially causing a process crash. Applications that supply an output buffer smaller than the input buffer face additional risk of an unbounded copy operation.

Beyond these patches, wolfSSH 1.6.0 also introduces enhanced security features. It now enables strict key exchange by default, offering additional protection against the Terrapin attack. The update also mandates RSA user authentication keys of at least 2048 bits and, by default, limits failed authentication attempts to six.

What You Should Do

  • Upgrade Immediately: All administrators and developers using wolfSSH should promptly upgrade their deployments to version 1.6.0.
  • Review Release Notes: Before rolling out the update, carefully review the official wolfSSH 1.6.0 release notes for any specific configuration changes or considerations.
  • Verify Application Callbacks: For the critical host key verification bypass, ensure that your application’s public-key-checking callback function is robust and performs thorough validation.
  • Review Forwarding Policies: If using SSH forwarding, confirm that your application’s forwarding policies are correctly implemented and enforced to prevent unauthorized channel requests.
  • Monitor Logs: Continuously monitor SSH server logs for any unusual activity, failed authentication attempts, or signs of compromise.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityVulnerability

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Malfex npm Malware Hides Executables in PNG Files to Infect Windows Devs

Next Post

Royal Navy Sailor Charged With Spying For Russia

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Malfex npm Malware Hides Executables in PNG Files to Infect Windows Devs
October 8, 2026
Critical Cisco Nexus Flaws Allow Root-Level Remote Code Execution
October 8, 2026
Top 10 Software Supply Chain Security Tools for 2026
October 8, 2026
Top Authors
David kimber
David kimber
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us