Skip to main content

Port Details

Port
22
Transport
TCP
Service
SSH
IANA service name
ssh
Range
System port (0-1023)
Related ports

Security Exposure

Internet-facing SSH services are a frequent target of password guessing and spraying; MITRE ATT&CK lists SSH on 22/TCP first among commonly targeted services. Weak passwords or permitted root logins turn that into direct shell access. Server flaws matter as well: in July 2024 the OpenSSH project disclosed a race condition in sshd 8.5p1 through 9.7p1 that could allow remote code execution as root on non-OpenBSD systems.

Hardening

  • +Set PasswordAuthentication to no and use public key or certificate authentication.
  • +Set PermitRootLogin to no or prohibit-password, and limit logins with AllowUsers or AllowGroups.
  • +Lower MaxAuthTries and use PerSourcePenalties on current OpenSSH releases to slow repeated failures.
  • +Track the OpenSSH security advisories and patch sshd promptly.
  • +Restrict port 22 to management networks, VPN users, or bastion hosts instead of the whole internet.

Monitoring

Collect sshd authentication logs and alert on bursts of failed logins, logins from new source addresses, and any root login. A spread of failures across many usernames from one source points to password spraying.

SSH Vulnerabilities

4 CVEs
CVETitleVendorCVSSEPSSKEVPublished
CVE-2026-67279
SSH Pre-Authentication Rekey State Bypass in MikroTik RouterOS
Mikrotik6.91.0%KEV2026-09-05
CVE-2026-86060
SSH session privilege manipulation via a crafted username in Mikrotik RouterOS
Mikrotik9.26.4%KEV2026-09-05
CVE-2025-32433
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
erlang10.098.8%KEV2025-04-16
CVE-2026-67276
SSH user impersonation possible in Mikrotik RouterOS
Mikrotik9.26.5%2026-09-05

Tools for Auditing and Monitoring SSH

Cowrie

Open Source
Honeypot & Deception Tools

Medium to high interaction SSH and Telnet honeypot that records attacker sessions.

LicenseBSD-3-Clause
PlatformLinux

Teleport

Free / Commercial
IAM Tools

Identity-aware access platform that issues short-lived certificates for SSH, Kubernetes, database, RDP, and web application access with session recording and audit.

LicenseAGPL-3.0-or-later (core); Apache-2.0 (API); modified Apache-2.0 (community builds); commercial (enterprise)
PlatformLinux, macOS, Windows

Hydra

Open Source
Password Cracking

Parallelized network login auditing tool that tests dozens of remote authentication protocols including SSH, SMB, RDP, HTTP, and database services.

LicenseAGPL-3.0-only with OpenSSL exception
PlatformLinux, macOS, Windows, BSD, Solaris

Frequently Asked Questions

Is SSH TCP or UDP?→

SSH runs over TCP. IANA registers port 22 for TCP, UDP, and SCTP, but RFC 4253 describes SSH over TCP/IP with servers listening on port 22.

Should port 22 be open to the internet?→

Exposure should be limited where possible, because SSH is among the services most targeted by password guessing (MITRE ATT&CK T1110.001). If it must be reachable, disable password logins and keep OpenSSH patched.

Does SFTP use port 22?→

Yes. SFTP runs inside an SSH session, so it uses the SSH port, which defaults to 22.

Which vulnerabilities affect the service on port 22?→

This database lists 4 CVEs related to SSH, 3 of them confirmed as exploited by CISA. Examples: CVE-2026-67279, CVE-2026-86060, CVE-2025-32433, CVE-2026-67276.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 22 is not guaranteed to be SSH. Exploited-in-the-wild data from the CISA KEV catalog (CC0).