Security scanners flag multiple OpenSSH vulnerabilities, specifically CVE-2026-35386, CVE-2026-35385, CVE-2026-35387, CVE-2026-35388, and CVE-2026-35414. Findings often indicate that the installed version of OpenSSH is prior to 10.3.
Symantec Identity Suite vApp r14.5.1 CHF02
The base operating system utilizes an OpenSSH package that requires specific security backports from the upstream repository to address identified vulnerabilities.
Apply cumulative OS patch CP-OS-14.5.1-20260508. This update installs openssh-9.9p1-8.el9, which contains the necessary security backports to remediate the reported CVEs.
Verify the remediation at the package level by executing the following command: rpm -q --changelog openssh | grep -i "CVE-2026-35387"
If the vulnerability scanner continues to flag the version string, provide documentation of the backported package as evidence of remediation.
Remediation is included in the cumulative OS patch mentioned above.
Subscribe to this Product and Article (reference: ) to receive updates regarding any further security package releases.