CVE-2016-7407 is a vulnerability in the dropbearconvert tool of the Dropbear SSH server, allowing code execution when converting a malicious key file. It was fixed in July 2016 and is flagged by Censys as exploited in the wild, though not in CISA's KEV catalog.