ZDI-26-710: NoMachine mDNS Heap-based Buffer Overflow Remote Code Execution Vulnerability
ZDI disclosed CVE-2026-92208, an unauthenticated heap-based buffer overflow in NoMachine's mDNS service enabling network-adjacent remote code execution (CVSS 8.8).
ZDI published advisory ZDI-26-710 describing a heap-based buffer overflow vulnerability in NoMachine's mDNS service, tracked as CVE-2026-92208 with CVSS 8.8. Network-adjacent attackers can execute arbitrary code on affected installations without authentication. The advisory does not mention observed exploitation or patch availability.
- Heap-based buffer overflow in NoMachine mDNS, CVE-2026-92208
- Unauthenticated network-adjacent RCE, CVSS 8.8
- No authentication required to exploit
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-92208 | NVD description · AI analysis pending | — | — | — | — | — |
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NoMachine. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-92208.
This source does not provide full text. Read it at zerodayinitiative.com.