ZeroHour
Product

NoMachine

2 mentions in 7 days · 2 in 30 days · 2 total · first seen · last

Timeline

ZDI-26-710: NoMachine mDNS Heap-based Buffer Overflow Remote Code Execution Vulnerability

ZDI disclosed CVE-2026-92208, an unauthenticated heap-based buffer overflow in NoMachine's mDNS service enabling network-adjacent remote code execution (CVSS 8.8).

ZDI published advisory ZDI-26-710 describing a heap-based buffer overflow vulnerability in NoMachine's mDNS service, tracked as CVE-2026-92208 with CVSS 8.8. Network-adjacent attackers can execute arbitrary code on affected installations without authentication. The advisory does not mention observed exploitation or patch availability.

ZDI-26-711: NoMachine Redis Improper Authentication Local Privilege Escalation Vulnerability

ZDI disclosed CVE-2026-92209, an improper authentication flaw in NoMachine's bundled Redis component allowing local privilege escalation (CVSS 7.8).

ZDI published advisory ZDI-26-711 describing an improper authentication vulnerability in the Redis component bundled with NoMachine, tracked as CVE-2026-92209 with CVSS 7.8. A local attacker who can already execute low-privileged code on the target system can escalate privileges. No in-the-wild exploitation or patch details are mentioned in the advisory.

Related CVEs

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.