Tokenpost High-Severity Telegram Desktop Vulnerability Allows Account Takeover
Article Content
- •CVE-2026-107181 affects Telegram Desktop versions 7.2.8 and earlier.
- •Attackers can exploit the flaw to steal session files via crafted links.
- •A patch was released on September 17, 2026, to mitigate the risk.
A high-severity vulnerability, tracked as CVE-2026-107181, was discovered in Telegram Desktop versions 7.2.8 and earlier, allowing potential account takeover under specific conditions. The flaw enables attackers to steal session files by tricking users into clicking a crafted external link that executes command injection. Users without a local password are particularly at risk. Telegram released a patch in version 7.2.9 on September 17, 2026, to address this vulnerability. A proof of concept for the exploit was made public on October 7, 2026, raising concerns about its potential exploitation in the wild.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-107181 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which versions of Telegram Desktop are affected?
What should users do to protect themselves?
Is there evidence of active exploitation?
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Sets Oct. 11 Deadline for Patching Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog after they were exploited by the China-linked group Flax Typhoon. Federal agencies must patch or retire the affected software by October 11, 2026. The vulnerabilities…