Microsoft Security Response Center Follow CVE-2026-59995 sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59995 msrc.microsoft.com