ZeroHour
ZDI Published Advisoriespublished ()ingested

ZDI-26-710: NoMachine mDNS Heap-based Buffer Overflow Remote Code Execution Vulnerability

AI summary · glm-5.3-flash

ZDI disclosed CVE-2026-92208, an unauthenticated heap-based buffer overflow in NoMachine's mDNS service enabling network-adjacent remote code execution (CVSS 8.8).

ZDI published advisory ZDI-26-710 describing a heap-based buffer overflow vulnerability in NoMachine's mDNS service, tracked as CVE-2026-92208 with CVSS 8.8. Network-adjacent attackers can execute arbitrary code on affected installations without authentication. The advisory does not mention observed exploitation or patch availability.

  • Heap-based buffer overflow in NoMachine mDNS, CVE-2026-92208
  • Unauthenticated network-adjacent RCE, CVSS 8.8
  • No authentication required to exploit

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-92208

NVD description · AI analysis pending
Full article

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NoMachine. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-92208.

This source does not provide full text. Read it at zerodayinitiative.com.