CVE-2026-41476Disclosure(deskflow / deskflow)

LOWCVSS 8.8 · HIGH

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Prioritize remediation for deskflow deskflow systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Deskflow is a keyboard and mouse sharing app. Prior to 1.26.0.138, a remote memory-safety vulnerability in Deskflow's clipboard deserialization allows a connected peer to trigger an out-of-bounds read by sending a malformed clipboard update. The issue is in the implementation of src/lib/deskflow/IClipboard.cpp. This is reachable because ClipboardChunk::assemble() in src/lib/deskflow/ClipboardChunk.cpp validates only the outer clipboard transfer size. It does not validate the internal structure of the serialized clipboard blob, so malformed inner lengths reach IClipboard::unmarshall() unchanged. This vulnerability is fixed in 1.26.0.138.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-120

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • deskflow

Threat summary

  • Active exploitation appears in 1 classified signals
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-04-25)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
deskflow

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-24: 1Mentions · 2026-04-25: 2Active Exploitation · 2026-04-25: 1Technical Details · 2026-04-24: 1Technical Details · 2026-04-25: 104-2404-25
Signal classification3 categories
Disclosure
133.3%
Active Exploitation
133.3%
General
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-241
Disclosure1
2026-04-252
Active Exploitation1General1
Full discourse3 posts
  • VulDB 🛡@vuldb
    Active Exploitation

    Our CTI team identified a lot of activities targeting Deskflow (CVE-2026-41476) https://vuldb.com/vuln/359565/cti

    Post summary

    CTI reports indicate widespread activity targeting Deskflow CVE‑2026‑41476, suggesting the vulnerability is being actively exploited, though no PoC, patch, or technical details are disclosed.

    0000060
    2.1K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-41476 Remote Memory-Safety Vulnerability in Deskflow Prior to 1... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41476 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The tweet flags CVE‑2026‑41476, a memory‑safety flaw in Deskflow, and links to a vulnerability detail page, but presents no PoC, exploit code, patch, or evidence of active exploitation.

    0000052
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-41476 Deskflow is a keyboard and mouse sharing app. Prior to 1.26.0.138, a remote memory-safety vulnerability in Deskflow's clipboard deserialization allows a connected pe… https://www.cve.org/CVERecord?id=CVE-2026-41476

    Post summary

    The post announces CVE‑2026‑41476, a remote memory‑safety flaw in Deskflow's clipboard deserialization affecting versions prior to 1.26.0.138.

    0000049
    57.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdeskflowdeskflow---

Explore more