Putty: community verdicts
3 notable / known-exploited Putty CVEs the community has triaged.
ⓘ Not an exhaustive list: we focus on the findings that matter (exploited / notable). For every Putty CVE, see NVD ↗.
- CVE-2026-48850LOW 3.7EPSS 0%
PuTTY 0.72 before 0.84 has a double free in RSA KEX.
- CVE-2026-48852LOW 3.7EPSS 0%
PuTTY 0.71 before 0.84 has an assertion failure in ECDSA signature verification.
- CVE-2026-48851LOW 3.1EPSS 0%
PuTTY 0.77 before 0.84 uses a copy of the PuTTY icon as a trust indication for TELNET data but the trust status is not cleared between proxy authentication and the main session.