Port 22: Secure Shell
Port 22 is the registered port for the Secure Shell (SSH) protocol, and RFC 4253 states that SSH servers normally listen on it. SSH provides encrypted remote login and other secure network services over an untrusted network (RFC 4251). SFTP file transfers also run inside SSH sessions on this port.
Port Details
Security Exposure
Internet-facing SSH services are a frequent target of password guessing and spraying; MITRE ATT&CK lists SSH on 22/TCP first among commonly targeted services. Weak passwords or permitted root logins turn that into direct shell access. Server flaws matter as well: in July 2024 the OpenSSH project disclosed a race condition in sshd 8.5p1 through 9.7p1 that could allow remote code execution as root on non-OpenBSD systems.
Hardening
- +Set PasswordAuthentication to no and use public key or certificate authentication.
- +Set PermitRootLogin to no or prohibit-password, and limit logins with AllowUsers or AllowGroups.
- +Lower MaxAuthTries and use PerSourcePenalties on current OpenSSH releases to slow repeated failures.
- +Track the OpenSSH security advisories and patch sshd promptly.
- +Restrict port 22 to management networks, VPN users, or bastion hosts instead of the whole internet.
Monitoring
Collect sshd authentication logs and alert on bursts of failed logins, logins from new source addresses, and any root login. A spread of failures across many usernames from one source points to password spraying.
SSH Vulnerabilities
4 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2026-67279 | SSH Pre-Authentication Rekey State Bypass in MikroTik RouterOS | Mikrotik | 6.9 | 1.0% | KEV | 2026-09-05 |
| CVE-2026-86060 | SSH session privilege manipulation via a crafted username in Mikrotik RouterOS | Mikrotik | 9.2 | 6.4% | KEV | 2026-09-05 |
| CVE-2025-32433 | Erlang/OTP SSH Vulnerable to Pre-Authentication RCE | erlang | 10.0 | 98.8% | KEV | 2025-04-16 |
| CVE-2026-67276 | SSH user impersonation possible in Mikrotik RouterOS | Mikrotik | 9.2 | 6.5% | 2026-09-05 |
Tools for Auditing and Monitoring SSH
Cowrie
Open SourceMedium to high interaction SSH and Telnet honeypot that records attacker sessions.
Teleport
Free / CommercialIdentity-aware access platform that issues short-lived certificates for SSH, Kubernetes, database, RDP, and web application access with session recording and audit.
Hydra
Open SourceParallelized network login auditing tool that tests dozens of remote authentication protocols including SSH, SMB, RDP, HTTP, and database services.
Related Tool Categories
Decoy services, deception platforms, and canary tokens that detect intruders with high-fidelity alerts.
Secrets managers, identity engines, and access control platforms for managing credentials and privilege.
Zero trust access, secure web gateways, firewalls, and perimeter enforcement platforms.
Frequently Asked Questions
Is SSH TCP or UDP?→
SSH runs over TCP. IANA registers port 22 for TCP, UDP, and SCTP, but RFC 4253 describes SSH over TCP/IP with servers listening on port 22.
Should port 22 be open to the internet?→
Exposure should be limited where possible, because SSH is among the services most targeted by password guessing (MITRE ATT&CK T1110.001). If it must be reachable, disable password logins and keep OpenSSH patched.
Does SFTP use port 22?→
Yes. SFTP runs inside an SSH session, so it uses the SSH port, which defaults to 22.
Which vulnerabilities affect the service on port 22?→
This database lists 4 CVEs related to SSH, 3 of them confirmed as exploited by CISA. Examples: CVE-2026-67279, CVE-2026-86060, CVE-2025-32433, CVE-2026-67276.
Sources
- IANA Service Name and Transport Protocol Port Number Registry (port 22)
- RFC 4253: The Secure Shell (SSH) Transport Layer Protocol
- RFC 4251: The Secure Shell (SSH) Protocol Architecture
- OpenSSH Security
- OpenBSD manual: sshd_config(5)
- MITRE ATT&CK T1110.001: Brute Force, Password Guessing
- UK Government Cyber Unit: Open port 21, File Transfer Protocol (FTP)
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 22 is not guaranteed to be SSH. Exploited-in-the-wild data from the CISA KEV catalog (CC0).