CVE-2025-26466
CVE-2025-26466: 3 tracked advisory records across Fortinet, NetApp, Red Hat. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Fortinet
1 advisory- Advisory severityMedium5.9
Medium [CVE-2025-26466] Pre-authentication Denial of Service attack in OpenSSH - CVE-2025-26466
FG-IR-25-122Source published Source updated
CVSSv3 Score: 5.9 CVE-2025-26466 A flaw was found in the OpenSSH package. For each ping packet the SSH server receives, a pong packet is allocated in a memory buffer and stored in a queue of packages. It is only freed when the server/client key exchange has finished. A malicious client may keep sending such packages, leading to an uncontrolled increase in memory consumption on the server side. Consequently, the server may become unavailable, resulting in a denial of service attack. Revised on 2026-05-25 00:00:00
- Related products — impact not confirmed
- No product details extracted. Check the source bulletin.
- Source-reported affected versions
- FortiADC 7.6: 7.6.1
- FortiADCManager 7.6: 7.6.0
- FortiAIOps 2.1: 2.1 all versions
- FortiAIOps 2.0: 2.0.1 through 2.0.2
1 more entries in the full advisory.
- Source-reported fixed versions
- FortiADC 7.6: 7.6.2
- FortiADCManager 7.6: 7.6.1
- FortiAIOps 2.1: migrate to a fixed release
- FortiAIOps 2.0: migrate to a fixed release
1 more entries in the full advisory.
- Mitigation guidance
- Upgrade per the Affected/Solution table: FortiADC 7.6: 7.6.2; FortiADCManager 7.6: 7.6.1; FortiAIOps 2.1: migrate to a fixed release; FortiAIOps 2.0: migrate to a fixed release; FortiAnalyzer 7.6: 7.6.3.
NetApp
1 advisory- Advisory severityMedium5.9
Medium [CVE-2025-26466] OpenSSH Vulnerability in NetApp Products
NTAP-20250228-0002Source published Source updated
Multiple NetApp products incorporate OpenSSH. OpenSSH versions 9.5p1 through 9.9p1 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). ONTAP 9: Affected only in version 9.16.1. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. Affected products named by the advisory: AFF Baseboard Management Controller (BMC) - A700s; AFF/ASA/FAS Baseboard Management Controller (BMC) - A1K/A90/A70/C80/FAS90/FAS70; AFF/ASA/FAS Baseboard Management Controller (BMC) - A50/A30/A20/C60/C30/FAS50; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; and 6 more.
- Affected products in this advisory
- AFF Baseboard Management Controller (BMC) - A700s
- AFF/ASA/FAS Baseboard Management Controller (BMC) - A1K/A90/A70/C80/FAS90/FAS70
- AFF/ASA/FAS Baseboard Management Controller (BMC) - A50/A30/A20/C60/C30/FAS50
- FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400
7 more entries in the full advisory.
- Source-reported affected versions
- 9.16.1
- Source-reported fixed versions
- ONTAP 9: 9.16.1P7
- ONTAP 9: 9.17.1
- Mitigation guidance
- Update affected NetApp products to a fixed release: ONTAP 9: 9.16.1P7, ONTAP 9: 9.17.1.
- NetApp HCI Compute Node (Bootstrap OS) has no planned fix; migrate to a supported release or product and consult NetApp's end-of-support notice.
Red Hat
1 advisory- Advisory severityMedium5.9
Medium [CVE-2025-26466] Openssh: denial-of-service in openssh
CVE-2025-26466Source published Source updated
A flaw was found in the OpenSSH package. For each ping packet the SSH server receives, a pong packet is allocated in a memory buffer and stored in a queue of packages. It is only freed when the server/client key exchange has finished. A malicious client may keep sending such packages, leading to an uncontrolled increase in memory consumption on the server side. Consequently, the server may become unavailable, resulting in a denial of service attack. The versions of OpenSSH as shipped with Red Hat Enterprise Linux 8 and older are not affected by this vulnerability. Also this issue marked as a moderate severity vulnerability rather than important because, while it enables a pre-authentication denial-of-service (DoS) attack, it does not allow remote code execution, privilege escalation, or…
- Affected products in this advisory
- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 9
- Red Hat package: openssh
- Source-reported affected versions
- Affected-version details not available in this record.
- Source-reported fixed versions
- openssh-0:9.9p1-7.el10_0
- openssh-0:8.7p1-45.el9
- RHBA-2025:6305
- RHSA-2025:6993
- Mitigation guidance
- This issue can be mitigated by setting the following three different options in the sshd configuration file located at: /etc/ssh/sshd_config MaxStartups: Set to a reasonable value, this option controls the maximum number of concurrent unauthenticated connections the SSH server accepts; PerSourcePenalties: Set its suboptions to a reasonable value, this option is used to help sshd to detect and drop connections that are potentially malicious for the SSH server; LoginGraceTime: Set to a resonable value, this option controls how much time the SSH server will wait the client to authenticate before dropping its connection; All the three option above needs to be set to implement a full mitigation for this vulnerability.
Android app · Google Play
Turn CVE research into alerts on your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.