April 2026 monthly report: open-source critical infrastructure - regreSSHion at year two
Two years after regreSSHion (CVE-2024-6387), the OpenSSH CVE that didn't quite weaponise globally - plus what CUPS, OpenSSL, and the rest of the critical OSS stack look like in April 2026.