# CVE-2026-45353

## Summary

- **CVE ID:** CVE-2026-45353
- **Severity:** CRITICAL
- **CVSS Score:** 9.3 (CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H)
- **CWE:** CWE-94, CWE-732, CWE-940
- **Published:** May 28, 2026
- **Last Modified:** May 28, 2026

## Description

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. From 3.0.6 to 3.8.8,  This vulnerability is fixed in 3.9.0.

## Affected Products

- electerm — electerm (>= 3.0.6, < 3.89.0)

## References

- [CNA](https://github.com/electerm/electerm/security/advisories/GHSA-7p5m-v798-f8vv)
- [CNA](https://github.com/electerm/electerm/commit/0599e67069b00e376a2e962649aaad6096e63507)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.11%
- **EPSS Percentile:** 1.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._