1 story taggedCVE-2026-55200.
A malicious SSH server can corrupt memory on any client built against libssh2 1.11.1 or earlier. No creds required.