CVE-2026-106588: OpenBSD OpenSSH

Low severity, CVSS 3.1. EPSS: 0.1% chance of exploitation in the next 30 days.

In sshd in OpenSSH through 10.6, use of the macOS 27 (or later) SDK has the side effect of loss of sandboxing, which is potentially unexpected.

Affected products

  • OpenBSD OpenSSH: up to and including 10.6

Published 2026-10-06. Last modified 2026-10-07.