WARNING: AnyDesk Linux Exploit Exposes Root Access Risk
A security vulnerability in AnyDesk's Linux software has been identified, with researchers releasing a proof-of-concept exploit called AnyPwn. The flaw allows for root-level command execution, though AnyDesk claims to have addressed the issue in a June 2026 update.
Why it matters
This highlights the critical risks of remote-support software and the importance of transparent security disclosures for enterprise IT infrastructure.
A working exploit for a vulnerability in AnyDesk’s Linux software has brought renewed scrutiny to a June update, raising questions about how organisations identify urgent security fixes when release notes provide little indication of their potential impact.
The development puts the focus on businesses that use remote-support software across Linux workstations and other managed systems. For those organisations, the immediate challenge is to establish which versions remain deployed, how they can be reached and whether updates have actually taken effect.
V12 researchers published AnyPwn on October 8. The exploit targets a heap buffer overflow in AnyDesk’s session protocol and demonstrates root-level command execution before authentication or connection approval.
The published implementation targets Linux version 8.0.2 over direct TCP connections to port 7070. Success depends on memory layout; unsuccessful attempts can crash the service. Exploitability of earlier releases has not been comprehensively confirmed.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in