OpenSSH vulnerabilities CVE-2026-35387 and others flagged by security scanners for 14.5.1 CHF02
search cancel

OpenSSH vulnerabilities CVE-2026-35387 and others flagged by security scanners for 14.5.1 CHF02

book

Article ID: 443809

calendar_today

Updated On:

Products

CA Identity Suite

Issue/Introduction

Security scanners flag multiple OpenSSH vulnerabilities, specifically CVE-2026-35386, CVE-2026-35385, CVE-2026-35387, CVE-2026-35388, and CVE-2026-35414. Findings often indicate that the installed version of OpenSSH is prior to 10.3.

 

Environment

 

Symantec Identity Suite vApp r14.5.1 CHF02

 

Cause

The base operating system utilizes an OpenSSH package that requires specific security backports from the upstream repository to address identified vulnerabilities.

 

Resolution

Apply cumulative OS patch CP-OS-14.5.1-20260508. This update installs openssh-9.9p1-8.el9, which contains the necessary security backports to remediate the reported CVEs.

Verify the remediation at the package level by executing the following command: rpm -q --changelog openssh | grep -i "CVE-2026-35387"

If the vulnerability scanner continues to flag the version string, provide documentation of the backported package as evidence of remediation.

 

Additional Information

Remediation is included in the cumulative OS patch mentioned above.

Subscribe to this Product and Article (reference: How to subscribe to a Knowledge Article) to receive updates regarding any further security package releases.