Security Advisory
IBM i and OpenSSH: multiple vulnerabilities
What Happened
IBM published a security bulletin covering four CVEs (CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388) affecting OpenSSH as shipped on IBM i, spanning permission handling, command execution, algorithm selection, and connection multiplexing weaknesses.
Why It Matters
SSH is a primary administrative and file-transfer access path on many IBM i shops that have moved off Telnet. Weaknesses in permission handling or command execution on the SSH stack directly affect the security of that access path.
Recommended Actions
- Match installed OpenSSH levels against IBM's affected-product table in the bulletin
- Apply the prescribed PTFs on every LPAR running SSH access
- Review SSH configuration for connection multiplexing settings called out in the bulletin
- Confirm no unmanaged or forgotten LPARs are still running unpatched OpenSSH