Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical AnyDesk Linux Vulnerability Allows Remote Code Execution

Critical AnyDesk Linux Vulnerability Allows Remote Code Execution

Posted on October 9, 2026 By CWS

A significant vulnerability in AnyDesk Linux has been identified, enabling remote attackers to execute commands with root privileges without requiring authentication. This issue, labeled ‘AnyPwn,’ affects AnyDesk version 8.0.2 and was resolved in version 8.0.3. Organizations using AnyDesk on Linux should prioritize updating their systems and ensure that TCP port 7070 is not exposed to unsecured networks.

Discovery and Immediate Response

The flaw was discovered by Rick de Jager from the V12 security team using their AI-driven platform, V12. The vulnerability was first made public in June, characterized as a pre-authentication, zero-click remote code execution weakness resulting from a heap buffer overflow. AnyDesk acknowledged the vulnerability promptly and released an update to address the issue. The public release of exploit code on October 8 has renewed focus on systems that have not yet been updated.

Technical Insights into the Vulnerability

According to technical documentation by V12 Security, the flaw resides in AnyDesk’s session protocol, which manages data during a remote connection. In the vulnerable version, the mode-5 stream packet handler fails to validate remote payload length properly. This oversight allows a calculation wrap-around, causing the application to allocate insufficient memory while treating it as a larger object, leading to an out-of-bounds write condition.

This vulnerability permits attackers to overflow memory and inject commands into the AnyDesk service, which operates with root privileges on Linux systems. This level of access could allow attackers to establish a stronghold on a system before any desktop-sharing request is accepted, bypassing common security safeguards like stolen credentials or user approval.

Exploitation and Mitigation Strategies

The exploit targets AnyDesk Linux 8.0.2 in service mode on x86_64 architectures, relying on specific memory layouts. Exploitation is not guaranteed, as an unsuitable memory layout may cause the service to crash instead. Additionally, the exploit’s reliance on exact build offsets means it cannot be generalized to all AnyDesk Linux versions.

For network exposure, direct threats are confirmed on TCP port 7070, though the vulnerability’s impact through relay connections remains partially unresolved. Administrators should update AnyDesk installations to 8.0.3 or later and limit inbound access to TCP/7070 until patching is complete. Reviewing service logs and monitoring for unusual root-level activities is also recommended.

The incident highlights the ongoing security challenges associated with remote-access software, which is frequently deployed on high-value infrastructure and trusted by IT departments. Previous reports have shown similar vulnerabilities in AnyDesk for Windows, underscoring the importance of comprehensive security practices.

Conclusion

This disclosure serves as a reminder of the critical role of timely software updates and vigilant security measures in protecting IT infrastructure. Organizations are urged to assess their exposure to this vulnerability and take immediate corrective actions to safeguard their systems.

Cyber Security News Tags:AnyDesk, buffer overflow, Cybersecurity, Linux, remote code execution, root access, security patch, software update, TCP port 7070, Vulnerability

Post navigation

Previous Post: Exploits Target AhsayCBS to Deploy Crypto Miners
Next Post: GitHub Action Flaw Exposes Thousands to Credential Theft

Related Posts

CISA Warns of Google Chrome 0-Day Vulnerability Exploited in Attacks CISA Warns of Google Chrome 0-Day Vulnerability Exploited in Attacks Cyber Security News
Gemini CLI Vulnerability Allows Hackers to Execute Malicious Commands on Developer Systems Gemini CLI Vulnerability Allows Hackers to Execute Malicious Commands on Developer Systems Cyber Security News
fsnotify Go Library Maintainer Changes Spark Security Concerns fsnotify Go Library Maintainer Changes Spark Security Concerns Cyber Security News
Microsoft SharePoint Vulnerability Heightens Security Risks Microsoft SharePoint Vulnerability Heightens Security Risks Cyber Security News
CISA Warns of TeleMessage TM SGNL Vulnerabilities Exploited in Attacks CISA Warns of TeleMessage TM SGNL Vulnerabilities Exploited in Attacks Cyber Security News
New AiTM Attack Campaign That Bypasses MFA Targeting Microsoft 365 and Okta Users New AiTM Attack Campaign That Bypasses MFA Targeting Microsoft 365 and Okta Users Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Autonomous AI Agents Pose New Cybersecurity Threats
  • OpenAI Dismisses Researchers Amid AI Safety Concerns
  • GitHub Action Flaw Exposes Thousands to Credential Theft
  • Critical AnyDesk Linux Vulnerability Allows Remote Code Execution
  • Exploits Target AhsayCBS to Deploy Crypto Miners

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Autonomous AI Agents Pose New Cybersecurity Threats
  • OpenAI Dismisses Researchers Amid AI Safety Concerns
  • GitHub Action Flaw Exposes Thousands to Credential Theft
  • Critical AnyDesk Linux Vulnerability Allows Remote Code Execution
  • Exploits Target AhsayCBS to Deploy Crypto Miners

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark