Termix maintains a narrowly scoped but prominently deployed product line centered on its core terminal and command-execution platform. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and cluster around authentication and access-control weaknesses—including authorization bypasses via user-controlled keys, OS command injection, improper access controls, certificate validation flaws, and cross-site scripting—reflecting the security-critical role of command execution and session management in the product's attack surface. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Termix over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-45748CRITICAL Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. The `POST /ssh/tunnel/connect` endpoint in Termix prior to version 2.3 | Jun 5, 2026 | 9.8 | 38 | NO | NO |
CVE-2026-45744CRITICAL Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.3.2, the GET /ssh/file_manager/ssh/resolvePath endp | Jun 5, 2026 | 9.9 | 38 | NO | NO |
CVE-2026-45750CRITICAL Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.3.2, the GET /ssh/file_manager/ssh/resolvePath endp | Jun 5, 2026 | 9.0 | 36 | NO | NO |
CVE-2025-59951CRITICAL Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. The official Docker image for Termix versions 1.5.0 and below, due to | Oct 1, 2025 | 9.1 | 36 | NO | NO |
CVE-2026-45746CRITICAL Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.3.2, the File Manager functionality in Termix conta | Jun 5, 2026 | 9.0 | 35 | NO | NO |
CVE-2026-45749HIGH Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. The `POST /users/totp/disable` and `POST /users/totp/backup-codes` end | Jun 5, 2026 | 8.1 | 32 | NO | NO |
CVE-2026-45743HIGH Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. 16 file-manager endpoints in Termix prior to version 2.3.2 do not veri | Jun 5, 2026 | 8.1 | 32 | NO | NO |
CVE-2026-45745HIGH Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Starting in version 1.7.0, Termix Desktop (Electron) disables TLS cert | Jun 5, 2026 | 8.0 | 32 | NO | NO |
CVE-2026-22804MEDIUM Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 1.7.0 to 1.9.0, Stored Cross-Site Scripting (XSS) vulnerability e | Jan 12, 2026 | 4.7 | 19 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Termix.
Media articles that mention a CVE ID that affects a product developed by Termix — matched by CVE ID, not by vendor name.