CVE-2026-7838Disclosure(uvnc / ultravnc)

LOWCVSS 8.7 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch uvnc ultravnc systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

UltraVNC viewer through 1.8.2.2 contains an integer overflow leading to a heap buffer overflow in the RFB protocol failure-response parsing path. In vncviewer/ClientConnection.cpp, the 4-byte network-supplied reasonLen field (type CARD32) is passed as reasonLen+1 to CheckBufferSize(). Because both operands are unsigned 32-bit, a reasonLen of 0xFFFFFFFF overflows to 0, causing CheckBufferSize to allocate only 256 bytes. The subsequent ReadString(m_netbuf, reasonLen) call then performs ReadExact for the original 4 GiB length into that 256-byte heap buffer. This overflow is reachable via rfbConnFailed (auth-scheme negotiation) and rfbVncAuthFailed (post-handshake) message types without successful authentication. A malicious VNC server, or any man-in-the-middle on the RFB stream, can trigger this condition when the victim viewer connects, potentially resulting in remote code execution as the user running the viewer. The crash was confirmed with AddressSanitizer on a portable reproduction harness (heap-buffer-overflow WRITE at offset 256).

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-190CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ultravnc

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
ultravnc

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-07-01: 2Patch / Workaround · 2026-07-01: 1Technical Details · 2026-07-01: 207-01
Signal classification1 categories
Disclosure
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • DACBARBOS® Brand@dacbarbos
    Disclosure

    RT @HugoValters CVE-2026-7838 - Critical RCE in UltraVNC viewer 1.8.2.2. Integer overflow causes heap buffer overflow in RFB failure-response parsing. CVSS 8.8. No patch available - disable or restrict access now. #CVE #UltraVNC #infosec https://www.valtersit.com/cve/CVE-2026-7838/

    Post summary

    The tweet announces CVE‑2026‑7838, a critical RCE in UltraVNC caused by an integer overflow leading to a heap buffer overflow, with a CVSS score of 8.8 and no patch yet available—users are advised to disable or restrict access as a workaround.

    0000150
    274 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨High - UltraVNC Viewer Integer Overflow → Heap Buffer Overflow in RFB Failure-Response Parsing (CVE-2026-7838) UltraVNC's viewer mishandles the failure-response path of the RFB protocol. The 4-byte, network-supplied reasonLen field is passed as reasonLen+1 to the buffer-size check; with a value of 0xFFFFFFFF the unsigned math wraps to 0, so only a 256-byte heap buffer is allocated. The code then tries to read the original ~4 GiB length into that tiny buffer — a heap buffer overflow. The bug is reachable pre-authentication via the rfbConnFailed and rfbVncAuthFailed message types, so a malicious VNC server (or a man-in-the-middle on the RFB stream) can trigger it the moment a victim connects, potentially leading to remote code execution as the user running the viewer. Exploitation requires the user to initiate a connection. 👉Affected: UltraVNC Viewer through 1.8.2.2 (no patched release confirmed yet).

    Post summary

    A new Integer Overflow/Heap Buffer Overflow in UltraVNC Viewer (CVE‑2026‑7838) allows remote code execution prior to authentication; no patch or PoC has surfaced yet.

    0000088
    232 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appuvncultravnc---

Explore more