CVE-2026-42454General

MEDIUMCVSS 9.9 · CRITICAL

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.1.0, all Docker container management endpoints in Termix interpolate the containerId URL path parameter and WebSocket message field directly into shell commands executed via ssh2.Client.exec() on remote managed servers without any sanitization or validation. An authenticated attacker can inject arbitrary OS commands by crafting a malicious container ID, achieving Remote Code Execution on any managed server. This issue has been patched in version 2.1.0.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 9 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • General: 5 classified signals
  • Disclosure: 3 classified signals
  • Peaked 3d ago at 3 mentions (2026-05-09); latest day: 1
  • 9 total mentions across 5 days

Deep dive

Activity timeline9 mentions / 5d
01223Mentions · 2026-05-08: 1Mentions · 2026-05-09: 3Mentions · 2026-05-13: 3Mentions · 2026-05-21: 1Mentions · 2026-06-12: 1Active Exploitation · 2026-05-09: 1Patch / Workaround · 2026-05-08: 1Patch / Workaround · 2026-05-09: 1Technical Details · 2026-05-08: 1Technical Details · 2026-05-09: 2Technical Details · 2026-05-13: 205-0805-0905-1305-2106-12
Signal classification3 categories
General
555.6%
Disclosure
333.3%
Active Exploitation
111.1%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-05-081
Disclosure1
2026-05-093
Active Exploitation1Disclosure1General1
2026-05-133
Disclosure1General2
2026-05-211
General1
2026-06-121
General1
Full discourse9 posts
  • Lyrie.ai@lyrie_ai
    General

    Unpopular opinion: The cybersecurity industry is selling you dashboards. The Unguarded API: Termix CVE-2026-42454 Puts Infrastructure Management Platforms at Extreme Risk

    Post summary

    The post mentions CVE-2026-42454 affecting Termix infrastructure management platforms without providing exploitation details, patches, or technical specifics.

    1000036
    267 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    CVE: CVE-2026-42454 CVSS: 9.9 (3.1) — CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities.

    Post summary

    A critical advisory for CVE-2026-42454 has been issued concerning Termix, yet no PoC, exploit, or mitigation details are supplied.

    1000039
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVSS 9.9 CRITICAL · CVE-2026-42454 · 9.9 → 2.1.0 CVE: CVE-2026-42454 CVSS: 9.9 (3.1) — CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The post announces the critical CVE-2026-42454 with a CVSS 9.9 rating and severity details, but no exploitation evidence, PoC, or patch information is supplied.

    1000032
    210 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-42454: Termix Docker Command Injection - What It Means for Your Business and How to Respond https://hubs.li/Q04hvy6F0

    Post summary

    The link references a CVE but does not provide any actionable details or evidence of exploitation.

    0000040
    31 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-42454-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The post includes only a link and minimal hashtags, providing no substantive details about the CVE.

    0000025
    210 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-42454 Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.1.0, all Docker container management … https://www.cve.org/CVERecord?id=CVE-2026-42454

    Post summary

    The post references CVE‑2026‑42454 for Termix, noting a pre‑2.1.0 issue and linking to the official CVE record, but offers no further technical or actionable context.

    0000091
    57.5K followersView on X
  • NerdieNews@NewsNerdie
    Active Exploitation

    ⚠️ CVE-2026-42454: Actively exploited Termix vulnerability in Docker endpoints allows attackers to inject OS commands, risking server control. Patch now to avoid compromise. #NerdieNews #CyberSecurity #InfoSec #Vulnerability #ICS #Kubernetes https://t.co/HIdZvVrZ3W

    Post summary

    CVE-2026-42454 details an actively exploited Termix flaw allowing OS command injection in Docker endpoints; a patch is urgently recommended to prevent full server takeover.

    0000038
    59 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-42454 Remote Code Execution via Command Injection in Termix Before Version 2.1.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42454

    Post summary

    The text discloses a command injection vulnerability (CVE‑2026‑42454) affecting Termix versions before 2.1.0 that enables remote code execution, but it does not reference active exploitation, patches, or proof‑of‑concept code.

    0000064
    4.0K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    🚨 CRITICAL — CVE-2026-42454 Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to … CVSS 9.9 🔴 No patch yet Full analysis → https://sec.kaitan.id/cves/CVE-2026-42454 #Docker #CyberSecurity #InfoSec

    Post summary

    The tweet announces the discovery of CVE‑2026‑42454, highlighting its high severity (CVSS 9.9) and noting that no patch is available yet, without providing PoC or exploit details.

    0000042
    90 followersView on X

Explore more