Any word on when OpenText will release updates to OpenSSH to resolve OpenSSH vulnerabilities (CVE-2025-26465 and CVE-2025-26466)?
Cybersecurity
DevOps Cloud
IT Operations Cloud
If an answer to your question is correct, click on "Verify Answer" under the "More" button. The answer will now appear with a checkmark. Please be sure to always mark answers that resolve your issue as verified. Your fellow Community members will appreciate it! Learn more
Any word on when OpenText will release updates to OpenSSH to resolve OpenSSH vulnerabilities (CVE-2025-26465 and CVE-2025-26466)?
https://www.suse.com/security/cve/CVE-2025-26465.html
https://www.suse.com/security/cve/CVE-2025-26466.html
look here and check which modules are affected in the OES
OES 25.1 uses
cat /etc/os-release
NAME="SLES"
VERSION="15-SP4"
VERSION_ID="15.4"
PRETTY_NAME="SUSE Linux Enterprise Server 15 SP4"
ID="sles"
ID_LIKE="suse"
ANSI_COLOR="0;32"
CPE_NAME="cpe:/o:suse:sles:15:sp4"
DOCUMENTATION_URL="">documentation.suse.com/"
“You can't teach a person anything, you can only help them to discover it within themselves.” Galileo Galilei
Thanks for providing details on how to identify affected modules on OES. This information can go under Tips in a separate article :)
Re CVE-2025-26466: It doesn't affect SLES 15 SP4 LTSS, the underlying OS for currently supported OES releases (2023 onwards).
Re CVE-2025-26465: Fix for this moderate severity issue will be included in the March drop of monthly OS updates.
Thanks.