Public exploit released for patched AnyDesk Linux flaw
Researchers published AnyPwn, a pre-auth root exploit for AnyDesk Linux 8.0.2, which was patched in 8.0.3 without a CVE.
On October 8, 2026, researchers published AnyPwn, a working proof-of-concept for a pre-authentication heap buffer overflow in AnyDesk for Linux's session protocol that can execute a command as root before a session is accepted. The public exploit targets build 8.0.2 over direct TCP port 7070, depends on memory layout, and may crash the service; full exploitation through AnyDesk relays was not demonstrated. AnyDesk fixed the issue in version 8.0.3 in June but described it only as a crash fix, with no CVE or security advisory. The Hacker News also cites 8.1.0 as the latest release and says the code was published on GitHub, details Cyber Security News does not include. The outlets disagree on credit: Cyber Security News names V12 Security researcher Rick de Jager as the finder, while The Hacker News refers only to the researchers who published the exploit. A separate heap overflow, CVE-2025-27918, was fixed earlier in version 7.0.0, and administrators who cannot patch should restrict access to TCP port 7070.
- On October 8, 2026, researchers published AnyPwn, a public proof-of-concept for a pre-authentication heap buffer overflow in AnyDesk for Linux's session protocol that can run a command as root.
- The public exploit targets Linux build 8.0.2 over direct TCP port 7070, is probabilistic and depends on heap layout, and may crash the service instead of succeeding.
- AnyDesk patched the flaw in version 8.0.3 in June but described it only as a crash fix, with no CVE or formal security advisory.
- The Hacker News cites 8.1.0 as the latest release and says the exploit was published on GitHub; Cyber Security News does not mention that version.
- Sources disagree on attribution: Cyber Security News says V12 Security researcher Rick de Jager found AnyPwn, while The Hacker News refers only to researchers who published it.
- Full exploitation through AnyDesk relays was not demonstrated; direct exposure of TCP port 7070 is the confirmed risk, and access to that port should be restricted if patching is not possible.
- A separate heap overflow, CVE-2025-27918, was fixed earlier in AnyDesk version 7.0.0.
Coverage timelineoldest first · each row is one article
- · 1d agoResearchers Publish Working Exploit for Pre-Auth AnyDesk Linux Flaw That Gives Root Access
The Hacker News· 67
Researchers released AnyPwn, a working pre-auth root exploit for AnyDesk Linux before 8.0.3.
- · 1d agoAnyDesk Linux Flaw Lets Remote Attackers Execute Code as Root Without Authentication
Cyber Security News· 68
A public proof-of-concept targets a patched AnyDesk Linux 8.0.2 flaw that can run commands as root without authentication.
Vulnerabilities in this storyAll →
- CVE-2025-279189.8<1%An issue was discovered in AnyDesk for Windows before 9.0.5, AnyDesk for macOS before 9.0.1, AnyDesk for Linux before 7.0.0, AnyDesk for iOS before 7.1.2, and…published · anydesk anydesk PoC
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-27918 |