EIP-2026-116371

PRE-CVE

Sysax Multi Server 6.40 - SSH Component Denial of Service

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-116371. PoCs published by 3unnym00n.

AI-analyzed exploit summary This exploit demonstrates a denial-of-service vulnerability in Sysax Multi Server 6.40 by sending a malformed SSH_MSG_USERAUTH_REQUEST packet with an improperly formatted username length. The exploit causes the SSH service to crash, resulting in the service becoming unavailable.

Description

Sysax Multi Server 6.40 - SSH Component Denial of Service

Exploits (1)

exploitdb WORKING POC
by 3unnym00n · pythondoswindows
https://www.exploit-db.com/exploits/38014

This exploit demonstrates a denial-of-service vulnerability in Sysax Multi Server 6.40 by sending a malformed SSH_MSG_USERAUTH_REQUEST packet with an improperly formatted username length. The exploit causes the SSH service to crash, resulting in the service becoming unavailable.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Moderate
Reliability
Reliable
Target: Sysax Multi Server 6.40
No auth needed
Prerequisites: Network access to the target server on port 22 · Sysax Multi Server with SSH enabled
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026