BREACH WATCH BRIEF Medium 🤖 Advisory

OpenSSH 10.6 Introduces Post‑Quantum Signature Algorithm and Deprecates Experimental Keys

OpenSSH 10.6 ships a hybrid post‑quantum signature algorithm and disables several legacy behaviours. Organizations must upgrade, regenerate keys, and document the change to maintain cryptographic governance and audit readiness.

SeverityMedium
Type🤖 Advisory
ConfidenceHigh
ReportedOct 7, 2026
Cloud & Infrastructure Providers Cloud infrastructure providers SaaS platforms Enterprise IT and security teams Vulnerability Exploit

What happened

The OpenSSH team released version 10.6, enabling the hybrid post‑quantum signature algorithm ssh‑mldsa44‑ed25519 and disabling unsafe compression, username handling, and credential storage behaviours. Experimental keys created with earlier post‑quantum support must be regenerated or removed.

Why it matters for trust and compliance

  • The update underscores the need for continuous cryptographic‑algorithm governance and documented change‑management, both core control objectives that map to many compliance frameworks.
  • Provides a concrete example of a control‑area (cryptographic algorithm governance) that must be continuously monitored and evidenced.
  • Creates audit‑ready evidence of patch management, key regeneration, and policy updates across frameworks.

Who is affected

Cloud infrastructure providers SaaS platforms Enterprise IT and security teams

Recommended actions

  1. Upgrade all OpenSSH instances to version 10.6.
  2. Identify and replace any keys generated with the experimental post‑quantum algorithm.
  3. Update cryptographic policies to reflect the newly supported algorithm and deprecate the experimental one.
  4. Record the upgrade, key regeneration, and policy change in your control‑evidence repository.

Get the Breach Digest

The incidents that matter for your vendors and your data, analysed for practitioners, in one email.