cyberinsider.com ViewSonic vCast Software Zero-Day Flaws Enable Device Takeover
Article Content
- •Three zero-day vulnerabilities in ViewSonic's vCast software disclosed.
- •Attackers can remotely view screens and install malicious apps on ViewBoards.
- •No vendor fix available; isolation and monitoring recommended.
Three zero-day vulnerabilities in ViewSonic's vCast software were disclosed by CERT/CC on September 24, 2026. These flaws, affecting ViewSonic ViewBoards, allow attackers on the same network to remotely view screens, install malicious Android applications, and potentially take full control of the devices. The vulnerabilities are identified as CVE-2026-82989, CVE-2026-82988, and CVE-2026-82987. Attackers can exploit these flaws by accessing exposed API endpoints, tricking devices into downloading malicious apps, and sending input commands without authentication. With no confirmed vendor fix, administrators are advised to isolate affected devices and monitor for suspicious activity. The vulnerabilities pose a significant risk of unauthorized access and lateral movement within networks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-82987 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in F5 BIG-IP APM Exploited for Remote Code Execution F5 Networks has reported a critical vulnerability in its BIG-IP Access Policy Manager (APM), tracked as CVE-2026-94127, which is being actively exploited in the wild. The flaw allows unauthenticated attackers to execute remote code on systems configured with both an APM access policy and an OAuth profile. This…
Massive Network of AI Proxy Servers Used for Malicious Activities Uncovered Security researchers from Team Cymru have identified over 10,000 proxy servers in China facilitating malicious AI activities. These servers, termed 'transfer stations,' are primarily used to bypass geographic restrictions and conduct model distillation attacks against frontier AI models. The infrastructure allows…