wolfSSH 1.6.0 fixes five flaws: a Critical client host-key check bypass that lets a man-in-the-middle impersonate an SSH server (CVE-2026-16516), a High Windows wolfSSHd login-token mix-up between users (CVE-2026-83540), and three Medium bugs
wolfSSL released wolfSSH 1.6.0 on 6 October 2026 with five security fixes. CVE-2026-16516 (Critical per wolfSSL): the client did not check that the ECDSA curve in a server's host key matched the negotiated algorithm, so a man-in-the-middle could swap in a key on another curve and pass signature verification with its own private key; it also needs the application to use a lax public-key check callback. Affects all versions through 1.5.0. CVE-2026-83540 (High): wolfSSHd on Windows shared one authentication context and its logon token across concurrent connections, so a user with a valid account could end up logged in as another, more privileged user (1.4.15 to 1.5.0; non-Windows builds unaffected). Medium: CVE-2026-84897 lets an unauthenticated client make a server run client-side DH group-exchange handling and costly primality checks (about half a second of CPU per 1 KB packet); CVE-2026-81535 admits forwarded-tcpip channels without the forwarding policy callback in --enable-fwd builds; CVE-2026-83742 is an SFTP path bug in wolfSSH_RealPath() that writes one NUL byte past a stack buffer and can crash the process. 1.6.0 also turns on strict key exchange (Terrapin protection) by default, requires RSA user keys of at least 2048 bits and limits failed logins to six. wolfSSH is mostly found embedded in devices and firmware, so fixes arrive through vendor updates. No exploitation is reported. Primary: wolfSSH GitHub release notes; wire: Cyber Security News.
- Product
- wolfSSH (embedded SSH client/server library) and wolfSSHd
- Versions
- Through 1.5.0 (ranges per CVE: 16516 all through 1.5.0; 83540 1.4.15–1.5.0 Windows; 84897 1.2.0–1.5.0; 81535 1.4.8–1.5.0 with --enable-fwd; 83742 1.4.11–1.5.0 non-Windows)
- CVSS
- Not scored by wolfSSL; severity Critical (CVE-2026-16516), High (CVE-2026-83540), Medium (three others)
- Exploited in Australia?
- unknown
- Patch to
- wolfSSH 1.6.0 or a vendor firmware that includes it. If you build with wolfSSH, also check your public-key check callback actually validates the host key.
Primary: wolfSSL — wolfSSH v1.6.0-stable release notes (6 Oct 2026) · Vendor: wolfSSL — security vulnerabilities list · CVE: CVE-2026-16516, CVE-2026-83540, CVE-2026-84897, CVE-2026-81535, CVE-2026-83742 · Cyber Security News — wolfSSH 1.6.0 fixes 5 security flaws (8 Oct 2026)
