You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
cve-2026-35414
About this tag
CVE-2026-35414 is a moderate-severity OpenSSH vulnerability affecting versions before 10.3 and Microsoft's Azure Linux 3.0 OpenSSH package. The flaw involves incorrect parsing of comma characters in SSH certificate principals when combined with authorized_keys principal restrictions. Microsoft updated its Security Update Guide on June 4, 2026 to address this issue. While not a critical remote code execution bug, it highlights how parsing assumptions in mature authentication systems can introduce risk. For WindowsForum readers, the practical concern is whether your environment uses SSH certificates in the specific way this bug requires. The advisory serves as a reminder to review certificate-based SSH configurations and apply the available updates.
Microsoft updated its Security Update Guide on June 4, 2026 for CVE-2026-35414, a Moderate OpenSSH flaw affecting versions before 10.3 and Microsoft’s Azure Linux 3.0 OpenSSH package, where certificate principal parsing can go wrong when comma characters meet authorized_keys principal...