Exploit Published for AnyDesk Linux Vulnerability
Article Content
- •A working exploit for a critical vulnerability in AnyDesk Linux has been published.
- •The flaw allows remote code execution before user approval, affecting version 8.0.2.
- •Administrators are advised to update to version 8.1.0 or restrict access to TCP port 7070.
Security researchers have released a working exploit for a pre-authentication remote code execution flaw in AnyDesk Linux 8.0.2, allowing attackers to gain root access before connection approval. The vulnerability, named AnyPwn, was patched in version 8.0.3 in June 2026, but no CVE has been assigned. The exploit targets a heap buffer overflow in AnyDesk's session protocol, specifically over direct TCP connections on port 7070. While the exploit is probabilistic and may not work on all builds, it demonstrates significant risk for users of the affected version. Administrators are urged to update to version 8.1.0 or restrict access to the vulnerable port. The researchers confirmed that the same code path may also be reachable via AnyDesk's relay servers. The vulnerability was first reported on June 22, 2026, but the lack of a formal advisory from AnyDesk raises concerns about awareness and response.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2025-27918 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which versions of AnyDesk are affected?
Is there a patch available?
What should I do if I can't update immediately?
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…