<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/update-openssh-now-to-prevent-man-in-the-middle-and-dos-attacks-upqsihl18" -->

---
title: Update OpenSSH Now to Prevent Man-in-the-Middle and DoS...
description: Security researchers from Qualys discovered two critical vulnerabilities in OpenSSH, identified as CVE-2025-26465 and CVE-2025-26466. These flaws could allow...
canonical: https://daily.dev/posts/update-openssh-now-to-prevent-man-in-the-middle-and-dos-attacks-upqsihl18
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Update OpenSSH Now to Prevent Man-in-the-Middle and DoS Attacks | daily.dev
og:description: Security researchers from Qualys discovered two critical vulnerabilities in OpenSSH, identified as CVE-2025-26465 and CVE-2025-26466. These flaws could allow...
og:url: https://daily.dev/posts/update-openssh-now-to-prevent-man-in-the-middle-and-dos-attacks-upqsihl18
og:image: https://api.daily.dev/og/posts/uPQsIHL18.png
og:image:alt: Update OpenSSH Now to Prevent Man-in-the-Middle and DoS Attacks
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Update OpenSSH Now to Prevent Man-in-the-Middle and DoS Attacks

**[Collections](https://daily.dev/sources/collections)** · 2 min read · 1 upvotes · 0 comments

## Summary

Security researchers from Qualys discovered two critical vulnerabilities in OpenSSH, identified as CVE-2025-26465 and CVE-2025-26466. These flaws could allow for man-in-the-middle (MitM) and denial-of-service (DoS) attacks, posing serious threats to secure communications. Users are urged to update to OpenSSH version 9.9p2, which includes the necessary patches to mitigate these risks.

## Content

# OpenSSH Patches Critical Vulnerabilities to Prevent Man-in-the-Middle and DoS Attacks

Two significant security flaws have been discovered in OpenSSH, identified as CVE-2025-26465 and CVE-2025-26466. These vulnerabilities could be exploited to facilitate man-in-the-middle (MitM) and denial-of-service (DoS) attacks, posing a considerable threat to systems relying on OpenSSH for secure communications.

## Description of Vulnerabilities

The flaws were brought to light by researchers from Qualys, who highlighted that the vulnerabilities affect OpenSSH clients when the `VerifyHostKeyDNS` feature is enabled. The MitM vulnerability (CVE-2025-26465) could allow attackers to intercept communication between clients and servers, enabling them to impersonate servers and manipulate transmitted data. This vulnerability has a severity score of 6.8.

On the other hand, the DoS vulnerability (CVE-2025-26466) could lead to prolonged outages by interrupting critical server maintenance. This vulnerability, which has a severity score of 5.9, could destabilize connections and significantly impact uptime for enterprises depending on OpenSSH.

## Impact and Mitigation

The exploitation of these vulnerabilities could have severe implications for enterprise security and operational uptime. The MitM bug, particularly notable for having been enabled by default on FreeBSD, allows attackers to control and modify data exchanged between servers and clients, disrupting secure connections. Similarly, the DoS flaw could be leveraged to shut down essential services, causing extended periods of downtime.

In response to these threats, OpenSSH has released version 9.9p2, which includes patches for both CVE-2025-26465 and CVE-2025-26466. Users are strongly advised to update their OpenSSH installations immediately to safeguard against these vulnerabilities.

## Conclusion

The recent discoveries of CVE-2025-26465 and CVE-2025-26466 in OpenSSH highlight the continuous need for vigilance and timely updates in cybersecurity. By applying the latest patches, users can protect their systems from potential MitM and DoS attacks, ensuring the integrity and availability of their secure connections.

For detailed instructions on updating OpenSSH to the latest version, please refer to the official OpenSSH documentation.

## Similar posts on daily.dev

- [Don’t just attend KubeCon \+ CloudNativeCon, Merge Forward your experience\!](https://daily.dev/posts/don-t-just-attend-kubecon-cloudnativecon-merge-forward-your-experience--l0rpp73x8) · CNCF · 1 upvotes · 0 comments
- [Announcing H2 2026 KCDs](https://daily.dev/posts/announcing-h2-2026-kcds-m96goajm1) · CNCF · 1 upvotes · 0 comments
- [Two months of Open Community Groups](https://daily.dev/posts/two-months-of-open-community-groups-asf52zhbs) · CNCF · 0 upvotes · 0 comments
- [CNCF Unveils Schedule for KubeCon \+ CloudNativeCon Europe 2026](https://daily.dev/posts/cncf-unveils-schedule-for-kubecon-cloudnativecon-europe-2026-ikhcoa5cb) · CNCF · 2 upvotes · 0 comments
- [CNCF Debuts KubeCon \+ CloudNativeCon Japan 2026 Schedule](https://daily.dev/posts/cncf-debuts-kubecon-cloudnativecon-japan-2026-schedule-xp5pyudub) · CNCF · 1 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#open-source](https://daily.dev/tags/open-source), [#linux](https://daily.dev/tags/linux), [#sysadmin](https://daily.dev/tags/sysadmin)

[View this post on daily.dev](https://daily.dev/posts/update-openssh-now-to-prevent-man-in-the-middle-and-dos-attacks-upqsihl18)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Update OpenSSH Now to Prevent Man-in-the-Middle and DoS Attacks","url":"https://daily.dev/posts/update-openssh-now-to-prevent-man-in-the-middle-and-dos-attacks-upqsihl18","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/update-openssh-now-to-prevent-man-in-the-middle-and-dos-attacks-upqsihl18"},"datePublished":"2025-02-18T17:11:15.049Z","dateModified":"2025-02-18T23:04:08.228Z","description":"Security researchers from Qualys discovered two critical vulnerabilities in OpenSSH, identified as CVE-2025-26465 and CVE-2025-26466. These flaws could allow...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/f5fa7d29d0b550cebf53677622462cea?_a=AQAEuj9","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/f5fa7d29d0b550cebf53677622462cea?_a=AQAEuj9","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/update-openssh-now-to-prevent-man-in-the-middle-and-dos-attacks-upqsihl18","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,open-source,linux,sysadmin","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"Update OpenSSH Now to Prevent Man-in-the-Middle and DoS Attacks"}]}
```

