OpenSSH Security Vulnerability Fixes for SteelHead Appliances Running RiOS 9.x

Solution Number:
S39202
Last Modified:
2026-09-23
Description
A custom RiOS 9.x build, RiOS 9.16.0b-cve1, has been released to address multiple OpenSSH security vulnerabilities identified in the software components used by Steelhead appliances.

This custom build provides security updates that remediate a set of Common Vulnerabilities and Exposures (CVEs) affecting OpenSSH. Customers running RiOS 9.x are encouraged to install this build to maintain the security posture of their Steelhead deployments and address vulnerability scan findings associated with the affected OpenSSH components.
Issue
Security assessments and vulnerability scans may identify multiple OpenSSH vulnerabilities on Steelhead appliances running RiOS 9.x releases prior to RiOS 9.16.0b-cve1.

To address these findings, Riverbed has released a custom build that includes fixes for the following CVEs:
  • CVE-2026-35385
  • CVE-2026-35386
  • CVE-2026-35387
  • CVE-2026-35388
  • CVE-2026-35414
  • CVE-2026-59995
  • CVE-2026-59996
  • CVE-2026-59997
  • CVE-2026-59998
  • CVE-2026-59999
  • CVE-2026-60000
  • CVE-2026-60001
  • CVE-2026-60002
Customers may observe these vulnerabilities being reported by security scanners or compliance tools. The RiOS 9.16.0b-cve1 custom build incorporates the necessary OpenSSH updates and security fixes to remediate these issues.
Solution
Upgrade the Steelhead appliance to RiOS 9.16.0b-cve1.

The custom build can be downloaded from the following location:

Download Link: RiOS 9.16.0b-cve1 Custom Build

Upgrade Recommendation:
  • Review existing maintenance windows and change management requirements.
  • Download the RiOS 9.16.0b-cve1 image from the provided link.
  • Perform the upgrade using the standard RiOS upgrade procedure applicable to your Steelhead model.
  • After the upgrade is complete, verify that the appliance is running RiOS 9.16.0b-cve1.
  • Re-run any vulnerability scans as needed to confirm remediation of the listed CVEs.
Additional Information: 
This custom build is intended specifically to address the OpenSSH-related security vulnerabilities listed in this article. Customers concerned about security scan findings associated with these CVEs should upgrade to RiOS 9.16.0b-cve1 at the earliest available maintenance opportunity.

If assistance is required with upgrade planning or deployment, please contact Riverbed Support.
Attachments
NOTICE: Riverbed® product names have changed. Please refer to the Product List for a complete list of product names.
Can't find an answer? Create a case