Denial-of-Service Vulnerability in AnyDesk by AnyDesk Software
CVE-2026-15682
Key Information:
Badges
What is CVE-2026-15682?
CVE-2026-15682 is a denial-of-service vulnerability affecting AnyDesk, a remote desktop software application widely utilized for remote access and remote support tasks. This vulnerability arises from a flaw in the Send Support Information feature, which allows local attackers to craft a denial-of-service condition by exploiting the software's handling of junction points. To successfully exploit this vulnerability, an attacker must have the ability to execute low-privileged code on the target machine. The consequence of this flaw could significantly disrupt operations, as it can render the AnyDesk application inoperable for legitimate users, thus interrupting critical remote support services.
Potential impact of CVE-2026-15682
-
Service Disruption: The primary impact of this vulnerability is the potential to cause denial-of-service conditions on systems running AnyDesk. This can interrupt remote work operations, affecting both internal and external support processes, leading to productivity loss.
-
Operational Security Risks: As AnyDesk is commonly used for remote access, its downtime might force organizations to seek alternative, potentially less secure methods of remote connectivity, introducing additional risks to security.
-
Reputation Damage: Organizations relying on AnyDesk for support and remote management may face reputational harm if service interruptions occur frequently, impacting customer trust and satisfaction.
Affected Version(s)
AnyDesk 9.0.4
News Articles
AnyDesk 0-Day Vulnerability Lets Attackers Trigger Denial-of-Service - IT Security News
A newly disclosed zero-day flaw in AnyDesk, tracked as CVE-2026-15682, allows local attackers to crash affected installations by abusing a core support feature, raising fresh concerns for organizations relying on the remote desktop tool for IT support and access management.β¦Read more β
3 weeks ago
AnyDesk 0-Day Vulnerability Lets Attackers Trigger Denial-of-Service
A newly disclosed zero-day flaw in AnyDesk, tracked as CVE-2026-15682, allows local attackers to crash affected installations.
3 weeks ago

References
CVSS V3.0
Timeline
- π
Vulnerability started trending
- πΎ
Exploit known to exist
- π°
First article discovered by Cybersecuritynews
Vulnerability published
Vulnerability Reserved