How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

USN-8721-1: OpenSSH vulnerabilities

calendar_today September 3, 2026 domain ubuntu

It was discovered that OpenSSH’s ssh-agent incorrectly handled interactions between agent locking and the session-bind@openssh.com extension. A remote attacker with access to a forwarded agent connection could possibly use this issue to perform operations that should only be available locally, such as adding tokens or using keys. (CVE-2026-73281) It was discovered that OpenSSH’s ssh client incorrectly handled concurrent remote-forwarding operations.

open_in_new Read original post