60
47
ZDI-26-710: NoMachine mDNS Heap-based Buffer Overflow Remote Code Execution Vulnerability
ZDI disclosed CVE-2026-92208, an unauthenticated heap-based buffer overflow in NoMachine's mDNS service enabling network-adjacent remote code execution (CVSS 8.8).
ZDI published advisory ZDI-26-710 describing a heap-based buffer overflow vulnerability in NoMachine's mDNS service, tracked as CVE-2026-92208 with CVSS 8.8. Network-adjacent attackers can execute arbitrary code on affected installations without authentication. The advisory does not mention observed exploitation or patch availability.
40
42
47
60
47