Microsoft Security Response Center Follow CVE-2026-60002 ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.) https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-60002 msrc.microsoft.com