Technology · Eugeny
Eugeny Tabby vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 13 vulnerabilities in Eugeny Tabby: 0 in the last 7 days and 5 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-68930, was published on 3 August 2026.
- Last 7 days
- 0
- Last 90 days
- 5
- Critical, all time
- 0
- Exploited in the wild
- 0
About Eugeny Tabby
Tabby (formerly Terminus) is a highly configurable terminal emulator, SSH and serial client for Windows, macOS and Linux.
Latest Eugeny Tabby vulnerabilities
- CVE-2026-68930: Eugeny Russh channel-scoped callback bypass for unopened channelsmediumCVSS 6.5
- Eugeny Russh panic in Curve25519 client key exchangemediumCVSS 5.3
- Russh denial of service via pty-req terminal-mode records overflowmediumCVSS 4.3
- Eugeny Russh denial of service via all-zero Curve25519 public valuemediumCVSS 5.3
- CVE-2026-46709: Eugeny Tabby OS command injection via drag-and-drop file pathhighCVSS 7.8
- CVE-2026-48108: Eugeny Russh resource exhaustion in SSH identification parsingmediumCVSS 5.3EPSS 0.1%
- CVE-2026-46705: Eugeny Russh authentication state mismatch in SSH servermediumCVSS 5.3
- CVE-2026-45038: Eugeny Tabby code execution via drag-and-drop control charactersinfoCVSS 8.4
- CVE-2026-45037: Eugeny Tabby unsafe protocol handler execution in terminal linkifierhighCVSS 7.1EPSS 0.0%
- CVE-2026-45036: Eugeny Tabby command injection via ZMODEM auto-confirmationhighCVSS 7
- CVE-2026-45035: Eugeny Tabby OS command injection in tabby:// URL schemeinfoCVSS 9.4
- CVE-2026-42189: Russh SSH library denial of service in keyboard-interactive authhighCVSS 7.5
- CVE-2024-48460: Eugeny Tabby credential exposure on host key verification failuremediumCVSS 4EPSS 0.4%
Most severe Eugeny Tabby vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-46709: Eugeny Tabby OS command injection via drag-and-drop file pathhighCVSS 7.8
- CVE-2026-42189: Russh SSH library denial of service in keyboard-interactive authhighCVSS 7.5
- CVE-2026-45037: Eugeny Tabby unsafe protocol handler execution in terminal linkifierhighCVSS 7.1EPSS 0.0%
- CVE-2026-45036: Eugeny Tabby command injection via ZMODEM auto-confirmationhighCVSS 7
- CVE-2026-68930: Eugeny Russh channel-scoped callback bypass for unopened channelsmediumCVSS 6.5
- CVE-2026-48108: Eugeny Russh resource exhaustion in SSH identification parsingmediumCVSS 5.3EPSS 0.1%
- Eugeny Russh panic in Curve25519 client key exchangemediumCVSS 5.3
- Eugeny Russh denial of service via all-zero Curve25519 public valuemediumCVSS 5.3
- CVE-2026-46705: Eugeny Russh authentication state mismatch in SSH servermediumCVSS 5.3
- Russh denial of service via pty-req terminal-mode records overflowmediumCVSS 4.3
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 1 | 0 | |
| 20 Jul 2026 | 3 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 1 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/tabby.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Eugeny Tabby vulnerabilities", https://junglewise.ai/threats/technologies/tabby, 26 September 2026.