cbcvebase.
CVE-2026-45745
published 2026-06-05

CVE-2026-45745: Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Starting in version 1.7.0, Termix Desktop…

PriorityP345high8CVSS 3.1
AVNACHPRNUIRSCCHIHAN
EPSS
0.17%
6.4th percentile
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Starting in version 1.7.0, Termix Desktop (Electron) disables TLS certificate validation, allowing a machine-in-the-middle attacker to intercept and modify HTTPS traffic to the configured Termix server. This can lead to credential theft and JWT/session theft during login and normal use. As of time of publication, no known patched versions are available.

Affected

2 ranges
VendorProductVersion rangeFixed in
termix-sshtermix
termixtermix>= 1.7.0
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.