On October 7, five vulnerabilities were reported in the wolfSSH library, with CVSS 4.0 scores ranging from 5.3 to 9.0. The most severe one concerns ECDSA key checking and could, under certain conditions, allow an attacker to impersonate a legitimate SSH server. The five vulnerabilities are CVE-2026-16516, CVE-2026-83540, CVE-2026-84897, CVE-2026-81535, and CVE-2026-83742.

wolfSSL describes the wolfSSH library as an SSHv2 implementation for clients and servers, with uses including embedded systems, file transfers, and port forwarding. The CVE listings list versions up to 1.5.0 as affected, and describe 1.6.0 as unaffected. However, the official product page still lists 1.5.0, so administrators should confirm that a newer version has been released before considering the upgrade available.
What problems have been identified in the wolfSSH library?
CVE -2026-16516 has a rating of 9.0 and affects SSH clients using ECDSA. In the wolfSSH library, the flaw involves failing to verify that the public key curve matches the algorithm negotiated by both parties. An attacker actively interfering with the connection could replace the key if the application uses weak server authentication. The CVE entry describes this condition, and the patch now links the curve to the agreed-upon algorithm.
This vulnerability does not mean that every SSH connection is automatically vulnerable. The risk increases when an application that integrates the wolfSSH library trusts a new key without rigorous verification or only compares part of its elements. Administrators should review how each application verifies the server key and avoid temporary settings that bypass this process.
CVE-2026-83540 concerns a different scenario: the wolfSSHd server on Windows. When using password or public key authentication, a user with a valid but lower level of access could confuse successive sessions and gain access with privileged account privileges. The vulnerability does not affect versions for other operating systems, according to the CVE entry, and is rated 7.7.
Risks before identification and in port forwarding
CVE -2026-84897 is rated 6.9 and could allow resource exhaustion before authentication. In a specific Diffie–Hellman key exchange configuration, an anonymous client could send a message that causes the server to perform expensive computations. The entry states that a packet of approximately 1 KB can take up to 5.8 seconds to process on a system that supports 8,192-bit numbers; in the default settings, the reported cost is less. The project code now rejects these messages, as shown in the related fix.
See also: MikroTik RouterOS: Active attacks via SSH without authentication

Another vulnerability, CVE-2026-81535, concerns port forwarding in installations compiled with the --enable-fwd. A malicious user on the other side of the connection could open unauthorized channels, resulting in unlimited memory and other resources being consumed. The entry gives a score of 6.3 and attributes the flaw to incomplete authorization checking and failure to map channels to authorized forwardings.
CVE-2026-83742 is found in the SFTP file path handling of the wolfSSH library on non-Windows systems. An authenticated user can send a path that causes a zero byte to be written beyond the boundary of a temporary table on the stack, potentially corrupting an adjacent value or terminating the process. The CVE description also notes a more severe risk for applications that call the public wolfSSH_RealPath() function with a smaller output table.
See also: MikroTrick chain allows attackers to take over MikroTik routers
What administrators should check
Organizations using the wolfSSH library must first identify the applications, devices, and embedded platforms that include it, as the same dependent library can be found in products from different vendors. Then, they need to check the exact version, enabled features, and how servers are authenticated.
For CVE-2026-84897, the logs suggest disabling the diffie-hellman-group-exchange-sha256if it is not needed. Reducing the maximum group size reduces processing time, but does not in itself prevent the affected message from being accepted. On Windows servers affected by CVE-2026-83540, limiting the accounts that are allowed to log in is a temporary measure, not a full fix.

There are already patch changes in the wolfSSH public repository for several of the issues, but the official product page still shows version 1.5.0. Therefore, development teams should confirm with the vendor which version or official update is available for their environment, evaluate the published fixes, and test each upgrade before installation.
See also: NatJack: New attacks affect TCP sessions and DNS
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The SecNews technical team recommends an immediate inventory of applications that integrate the wolfSSH library and checking authentication and forwarding settings. Priority is given to client applications that use ECDSA with relaxed key verification and Windows servers that accept connections from multiple accounts. Administrators should monitor official updates and apply fixes as soon as they confirm a compatible version.
