Find notable cyber news and cases, enriched with sources, timelines, and signals.

AnyDesk Linux pre-auth RCE flaw (published exploit)

Vulnerability
First reported
Last updated
Happening score
H score 29
1 unique sources, 1 articles

Summary

Hide ▲

A working exploit is now public for an AnyDesk Linux pre-authentication remote code execution flaw, exposing systems to root access before connection approval. AnyDesk fixed the issue in version 8.0.3 in June, but the flaw still had no CVE as of October 9. The published code targets direct TCP connections on port 7070 and shows that the bug can be weaponized even before a session is accepted. Relay-based exploitation remains unresolved.

Timeline

  1. 09.10.2026 15:59 2 articles · 4h ago

    AnyPwn exploit code is released on GitHub

    Technical Analysis Update

    Researchers released AnyPwn on GitHub, publishing a working exploit for the heap buffer overflow in AnyDesk's session protocol that targets AnyDesk Linux 8.0.2 and can execute commands as root over direct TCP connections on port 7070.

    Show sources
  2. 09.10.2026 03:00 1 articles · 17h ago

    AnyDesk Linux flaw remains without a CVE or formal advisory

    Untyped Phase

    As of October 9, the AnyDesk Linux vulnerability still had no CVE and no formal security advisory, and the researchers said the published exploit worked only over direct TCP connections on port 7070 while relay-based full exploitation remained unresolved.

    Show sources