ZDI-26-712: NoMachine nxhtd Server-Side Request Forgery Information Disclosure Vulnerability
ZDI disclosed CVE-2026-92210, an unauthenticated server-side request forgery in NoMachine's nxhtd server leading to information disclosure (CVSS 7.2).
ZDI published advisory ZDI-26-712 describing a server-side request forgery vulnerability in NoMachine's nxhtd server, tracked as CVE-2026-92210 with CVSS 7.2. Remote attackers can initiate arbitrary server-side requests without authentication, resulting in information disclosure. The advisory does not state whether exploitation has been observed or a patch released.
25