Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-106589 is a least privilege violation vulnerability in OpenSSH through version 10.6 affecting sshd sessions in certain environments such as QNX 6 and SCO OpenServer 5. The issue arises due to the interaction of GatewayPorts and StreamLocalForwarding options combined with lack of support for file-descriptor passing and unprivileged PTY allocation, causing sshd-session to unexpectedly have root privileges. The vulnerability has a low CVSS score of 2.9 and does not impact confidentiality or availability but may allow limited integrity impact. No known exploits or patches are currently documented. Join the discussion | CVE Database V5 | 10/06/2026, 21:21:35 UTC Added: 10/06/2026, 21:33:58 UTC |
0 CVE-2026-106588 is a low-severity vulnerability in OpenSSH through version 10.6 related to improper isolation or compartmentalization. Specifically, when sshd is built using the macOS 27 (or later) SDK, sandboxing is lost, which may be unexpected behavior. This could lead to a reduction in security isolation but does not directly impact confidentiality or availability. Join the discussion | CVE Database V5 | 10/06/2026, 21:10:00 UTC Added: 10/06/2026, 21:33:58 UTC |
0 CVE-2026-106587 is a type confusion vulnerability in OpenSSH's sshd component before version 10.6. The issue arises because the configuration option value "none" is sometimes incorrectly interpreted as a filename instead of indicating that a feature is disabled. This can lead to unintended behavior in the sshd service. Join the discussion | CVE Database V5 | 10/06/2026, 21:01:44 UTC Added: 10/06/2026, 21:33:58 UTC |
0 CVE-2026-106586 is a low-severity vulnerability in OpenSSH versions before 10.6 where the 'restrict' keyword in authorized_keys did not apply to tunnel forwarding as intended. This represents an incorrect control flow implementation issue distinct from CVE-2026-73283. Join the discussion | CVE Database V5 | 10/06/2026, 20:57:09 UTC Added: 10/06/2026, 21:04:05 UTC |
0 CVE-2026-106585 is a vulnerability in OpenSSH versions before 10.6 where the sshd and ssh components do not verify if the maximum packet length is exceeded during decompression of highly compressed data. This improper handling can lead to data amplification issues. The vulnerability has a medium severity with a CVSS score of 6.5. Join the discussion | CVE Database V5 | 10/06/2026, 20:52:39 UTC Added: 10/06/2026, 21:04:05 UTC |
0 An off-by-one error (CWE-193) in ssh-keygen in OpenSSH versions before 10.6 causes certificates to have incorrect expiration times due to mishandling of Daylight Saving Time. This issue may have a slightly more severe impact on users in some Antarctic locations. The vulnerability has a low CVSS score of 2.5 and does not affect confidentiality or availability, only integrity to a limited extent. Join the discussion | CVE Database V5 | 10/06/2026, 20:47:50 UTC Added: 10/06/2026, 21:04:05 UTC |
0 CVE-2026-106582 is a low-severity vulnerability in OpenSSH versions before 10.6 where the use of an LZ77 dictionary coder creates a covert channel, contrary to findings in the research paper arXiv 2609.07709 "Crossing the Streams." This vulnerability affects OpenSSH's sshd and ssh components. Join the discussion | CVE Database V5 | 10/06/2026, 20:35:32 UTC Added: 10/06/2026, 20:49:08 UTC |
0 CVE-2026-106555 is a low-severity vulnerability in OpenSSH versions before 10.6 where the GSSAPIAuthentication state can be incorrectly persisted across authentication attempts in sshd. This issue relates to improper resource transfer between security spheres, potentially allowing authentication state leakage. The vulnerability has a CVSS score of 2.2, indicating low impact, with limited confidentiality impact and no integrity or availability impact reported. Join the discussion | CVE Database V5 | 10/06/2026, 20:28:56 UTC Added: 10/06/2026, 20:49:08 UTC |
0 CVE-2026-106553 is a low severity vulnerability in OpenSSH versions before 10.6 where credentials may incorrectly persist after a failed GSSAPIAuthentication attempt. This issue relates to improper resource handling in sshd, potentially allowing credential persistence beyond intended scope. Join the discussion | CVE Database V5 | 10/06/2026, 20:25:45 UTC Added: 10/06/2026, 20:49:08 UTC |
CVE-2026-106552 is a relative path traversal vulnerability in the sftp component of OpenSSH versions before 10.6. It allows a server to cause files to be written to unintended locations during a recursive copy operation. The vulnerability has a medium severity with a CVSS score of 4.2. Join the discussion | CVE Database V5 | 10/06/2026, 20:20:31 UTC Added: 10/06/2026, 20:49:08 UTC |
Showing 1 to 10 of 16 results