CVE-2026-4115 – PuTTY

CVSS 3.7 LOW

“Even low-severity trust weaknesses deserve attention when public exploit code is available.”

A patch was released for a vulnerability affecting PuTTY. CVE-2026-4115 has a CVSS score of 3.7, which is Low severity.

The vulnerability involves improper verification of cryptographic signatures and trust validation mechanisms. Public proof-of-concept code is available. Successful exploitation could allow attackers to undermine authentication assurances or trust decisions in affected PuTTY environments. The update strengthens signature verification and authentication integrity protections.

Key Details

Affected Product
Putty Putty
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
CWE Classification
CWE-345
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.