wolfSSH 1.6.0 Addresses Five Vulnerabilities, Including Critical MITM Bypass
The wolfSSH library has been updated to version 1.6.0, patching five security vulnerabilities, with the most critical allowing for man-in-the-middle attacks and server impersonation.

wolfSSL has released wolfSSH version 1.6.0, a significant update that addresses five security vulnerabilities discovered in its SSH implementation. The release, published on October 6, 2026, includes fixes for a critical man-in-the-middle (MITM) host key verification bypass, a high-severity Windows privilege escalation flaw, and three medium-severity issues.
The most critical vulnerability, tracked as CVE-2026-16516, affects wolfSSH versions up to 1.5.0. This flaw arises during the SSH key exchange process where the client fails to adequately verify if the ECDSA curve within the server's host key aligns with the algorithm negotiated for the connection. An attacker in a privileged network position could potentially substitute the legitimate host key with one they control, using a different curve. While signature verification might still pass due to the attacker possessing the private key, successful exploitation also hinges on a weak public-key-checking callback within the application, meaning not all affected clients are automatically vulnerable.
The high-severity vulnerability, CVE-2026-83540, impacts the wolfSSHd daemon on Windows systems running versions 1.4.15 through 1.5.0. This issue stems from a shared authentication context that included a Windows logon token across concurrent connections. Both password and public key authentication methods wrote to this shared token, creating a scenario where a legitimate user could inadvertently inherit the identity, including elevated privileges, of another user. Notably, this vulnerability does not affect non-Windows builds of wolfSSHd.
Three medium-severity vulnerabilities were also resolved in this update. CVE-2026-84897 addresses an issue with how Diffie-Hellman group exchange messages were handled. A vulnerable server could accept messages intended solely for server-side processing, enabling an unauthenticated client to trigger computationally expensive prime checks on chosen groups. This could lead to denial-of-service conditions by consuming significant CPU resources. CVE-2026-81535, affecting versions 1.4.8 through 1.5.0 when compiled with forwarding enabled, allowed the software to accept forwarded-tcpip channel requests without validating the application's forwarding policy, potentially leading to unauthorized resource allocation. Lastly, CVE-2026-83742, present in non-Windows builds from versions 1.4.11 through 1.5.0, involves incorrect length calculations in the wolfSSH_RealPath() function. This could allow a crafted SFTP path to overwrite data beyond a stack buffer, leading to process crashes and potential data corruption.
Developers and administrators are strongly advised to upgrade to wolfSSH 1.6.0 to mitigate these risks. The update not only fixes these specific flaws but also enhances security by enabling strict key exchange by default, offering protection against attacks like Terrapin. Additionally, it enforces a minimum of 2048 bits for RSA user authentication keys and limits failed authentication attempts to six by default, further hardening the SSH implementation.
This comprehensive patch addresses a range of security concerns, from critical MITM capabilities to privilege escalation and denial-of-service vectors, underscoring the importance of keeping SSH implementations up-to-date. The disclosure highlights the ongoing efforts by researchers and vendors to identify and remediate vulnerabilities in widely used network protocols.