TS-2026-009: Insecure argument handling in Tailscale SSH permitted root access

Tailscale has released version 1.66.0 to patch a security vulnerability that could allow unauthorized root access via insecure argument handling in SSH. The flaw affected Linux-based exit nodes and subnet routers using default ACL configurations.
Why it matters
This is a critical security update for users of the Tailscale mesh VPN, as the vulnerability could potentially allow attackers to bypass network access controls.
Description : Insufficient inbound packet filtering in subnet routers and exit nodes
Technical advisory reporting is objective and focused on security remediation.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in