#SSH
All CosmicBytez Labs articles tagged #SSH, across news, security advisories, how-to guides, and projects.
- Security
CVE-2026-86060: MikroTik RouterOS SSH Privilege Escalation
Unauthenticated attackers can escalate to full admin control on MikroTik RouterOS via a crafted SSH username; CISA lists it as actively exploited.
- News
Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication
CERT Polska warns of active attacks gaining full admin control of internet-facing MikroTik RouterOS devices via SSH with no authentication needed.
- Security
CVE-2026-53545: Termix SSH Tunnel Command Injection — CVSS 9.8 Critical
Critical OS command injection in Termix's SSH tunnel teardown lets authenticated attackers execute arbitrary OS commands on hosts. Patch to 2.3.2.
- Security
CVE-2026-53546: Termix WebSocket Host Bypass Grants Cross-User SSH Access
Termix terminal WebSocket accepts attacker-controlled host IDs without ownership checks, enabling cross-user SSH access to any managed server. CVSS 9.6.
- Security
CVE-2026-53548: Termix IDOR Exposes All Stored SSH Passwords to Any User
Termix's password endpoint returns decrypted SSH credentials for any host ID without ownership verification, exposing all stored passwords. CVSS 9.6.
- Security
CVE-2026-75627: Bastillion Authentication Bypass via Path Traversal
Bastillion's controller dispatcher fails to validate URI paths, letting unauthenticated attackers bypass auth filters and access administrative functions.
- HOWTO
OpenSSH Hardening with Certificate-Based Authentication
Replace static SSH keys with a short-lived certificate authority. Harden sshd_config, eliminate lateral-movement risk, and enforce zero-trust access...
- Security
CVE-2026-58065: Apache Airflow Git Provider Disables SSH Host Key Verification
The Apache Airflow Git provider runs git-over-SSH with StrictHostKeyChecking=no by default, allowing a network-position attacker to silently impersonate...
- News
Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw
A heap overflow in libssh2's transport layer allows a malicious SSH server to achieve pre-authentication RCE against any connecting client. All versions...
- Project
Teleport PAM: Zero-Trust Privileged Access for Your Homelab
Deploy Teleport's open-source privileged access management platform to replace static SSH keys with short-lived certificates, enforce MFA, record every...
- Security
CVE-2025-15638: Net::Dropbear Bundles Vulnerable
Net::Dropbear versions before 0.14 for Perl ship with Dropbear 2019.78 or earlier, which includes libtomcrypt v1.18.1 — a library affected by two known...
- HOWTO
SSH Hardening Best Practices
Secure your SSH servers with essential hardening techniques including key-based authentication, fail2ban configuration, and advanced security measures.