Skip to content
Exploit Published for AnyDesk Linux Vulnerability

Exploit Published for AnyDesk Linux Vulnerability

First seen 9 Oct 2026, 14:34 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 9, 2026 at 15:40 UTC
  • •A working exploit for a critical vulnerability in AnyDesk Linux has been published.
  • •The flaw allows remote code execution before user approval, affecting version 8.0.2.
  • •Administrators are advised to update to version 8.1.0 or restrict access to TCP port 7070.

Security researchers have released a working exploit for a pre-authentication remote code execution flaw in AnyDesk Linux 8.0.2, allowing attackers to gain root access before connection approval. The vulnerability, named AnyPwn, was patched in version 8.0.3 in June 2026, but no CVE has been assigned. The exploit targets a heap buffer overflow in AnyDesk's session protocol, specifically over direct TCP connections on port 7070. While the exploit is probabilistic and may not work on all builds, it demonstrates significant risk for users of the affected version. Administrators are urged to update to version 8.1.0 or restrict access to the vulnerable port. The researchers confirmed that the same code path may also be reachable via AnyDesk's relay servers. The vulnerability was first reported on June 22, 2026, but the lack of a formal advisory from AnyDesk raises concerns about awareness and response.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2025-11-06
CVE-2025-27918 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-22
Vulnerability reported
Researchers disclosed a pre-authentication remote code execution flaw in AnyDesk Linux 8.0.2.
The Hacker News
2026-06-30
Patch released
AnyDesk released version 8.0.3 to address the vulnerability but did not assign a CVE.
The Hacker News
2026-10-08
Exploit published
Researchers released a working proof-of-concept exploit for the vulnerability on GitHub.
GitHub

More articles in this cluster (2)

Following this threat?

Track CVE-2025-27918 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions of AnyDesk are affected?
AnyDesk Linux version 8.0.2 is affected; version 8.0.3 and later are not.
Is there a patch available?
Yes, AnyDesk released version 8.0.3 in June 2026 to fix the vulnerability.
What should I do if I can't update immediately?
Restrict access to TCP port 7070 to mitigate potential exploitation.