Tracked as CVE-2026-35414 (CVSS score of 8.1), the flaw is described as a mishandling of the authorized_keys principals option in certain scenarios involving certificate authorities (CA) that use comma characters.
According to Cyera, because of the bug, a comma in an SSH certificate principal name leads to OpenSSH access control bypass, allowing users to authenticate as root on a vulnerable server, as long as they have a valid certificate from a trusted CA.
"And on the third day God separated the land and sea to create the continents and oceans. Some say he did a great job, I could do better, many have said it. He put the Strait of Hormuz in Iran, I wouldn't have done that, bad move. Thank you for your attention to this matter."
TLDR; They were probably not horribly painted given the evidence from other types of surviving artwork from the period