Qualys dropped another two OpenSSH vulns this week - CVE-2025-26465 & CVE-2025-26466
I don’t think either are bad, you should keep calm and patch as per usual.
The first one needs a non-default config, and PoC for the second also uses a non-default config. Neither are RCE and I doubt will ever see in the wild exploitation.
Proof of concept: https://www.qualys.com/2025/02/18/openssh-mitm-dos.txt
GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.
All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.