WOLFSSL released wolfSSH 1.6.0 to fix five security flaws in the lightweight SSH library. The most serious is CVE-2026-16516, a 9.0-graded (CVSSv4) issue described as an ECDSA host key curve not being validated against the negotiated algorithm, which could allow a man-in-the-middle attacker to pass off a forged server key. The advisory notes that all five flaws affect wolfSSH 1.5.0 and earlier, and that no exploitation has been publicly confirmed at this time.
The other notable flaws addressed in the release include CVE-2026-83540 (Windows race condition leading to logon token reuse across connections), CVE-2026-84897 (pre-authentication CPU drain from unauthenticated clients triggering large primes during key exchange), CVE-2026-81535 (unbounded forwarding channels and lack of proper channel verification), and CVE-2026-83742 (unsigned null write caused by a crafted SFTP path on non-Windows platforms). The reported severities range from high to medium, and the page states that there is no confirmed exploitation yet.
Affected versions span multiple release lines before 1.6.0, with specific ranges given per CVE. The recommended action is to upgrade to wolfSSH 1.6.0 to close all five vulnerabilities, after which device makers should rebuild and ship firmware with the updated library. In the interim, the article suggests using strict host key checks in client code rather than trust-on-first-use, and disabling port forwarding if it is not required. The report credits several researchers for reporting the bugs.
The content emphasises that while the CVEs cover both client and server functionality, public exploitation remains unconfirmed. The UK date for the story is 8 October 2026.