A notice published on September 29, 2026 reports a possible authentication bypass in specific SSH server implementations using Apache MINA SSHD’s sshd-core. The flaw is rated CVSS 3.1 9.1.
The notice describes CVE-2026-77185 as a critical flaw in a specific, presumably rare, way of implementing an SSH server with Apache MINA SSHD’s sshd-core. Under these conditions, asynchronous authentication can bypass signature verification. The stated rating is CVSS 3.1: 9.1, with vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N.
Affected versions are 2.0.0 up to, but not including, 2.20.0, and 3.0.0-M1 up to, but not including, 3.0.0-M6. Since the available text is an automatic translation and omits technical details, consult the original oss-sec notice and confirm exposure and the fixed version in official Apache MINA SSHD documentation before taking action.