Security Advisory

IBM i and OpenSSH: multiple vulnerabilities

High Last verified

What Happened

IBM published a security bulletin covering four CVEs (CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388) affecting OpenSSH as shipped on IBM i, spanning permission handling, command execution, algorithm selection, and connection multiplexing weaknesses.

Why It Matters

SSH is a primary administrative and file-transfer access path on many IBM i shops that have moved off Telnet. Weaknesses in permission handling or command execution on the SSH stack directly affect the security of that access path.

Recommended Actions

  • Match installed OpenSSH levels against IBM's affected-product table in the bulletin
  • Apply the prescribed PTFs on every LPAR running SSH access
  • Review SSH configuration for connection multiplexing settings called out in the bulletin
  • Confirm no unmanaged or forgotten LPARs are still running unpatched OpenSSH

Sources