CVE-2026-7840Disclosure(uvnc / ultravnc)

LOWCVSS 9.3 · CRITICAL

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

UltraVNC repeater through 1.8.2.2 contains a global buffer overflow in its embedded HTTP administration server. The functions wi_senderr() and wi_replyhdr() in repeater/webgui/webutils.c write the caller-supplied HTTP request URI into a fixed 1000-byte global buffer (hdrbuf) via unchecked sprintf calls. The HTTP receive buffer accepts URIs up to approximately 150 KB (WI_RXBUFSIZE = 153600), so an unauthenticated attacker who can reach the repeater HTTP port (default TCP 80) can overflow hdrbuf by at least 500 bytes with a single HTTP request containing a URI of 1500 bytes or longer, corrupting adjacent .bss-segment globals. The overflow occurs before any authentication check, making it reachable without credentials. A remote, unauthenticated attacker can achieve arbitrary code execution on the host running the repeater.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ultravnc

Threat summary

  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked at 4 mentions on most recent observed day (2026-07-22)
  • 6 total mentions across 2 days

Affected systems

Vendors
Products
ultravnc

Deep dive

Activity timeline6 mentions / 2d
01234Mentions · 2026-07-03: 2Mentions · 2026-07-22: 4Technical Details · 2026-07-03: 2Technical Details · 2026-07-22: 407-0307-22
Signal classification2 categories
Disclosure
583.3%
General
116.7%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-07-032
Disclosure2
2026-07-224
Disclosure3General1
Full discourse6 posts
  • YogSotho@YogSoth0
    Disclosure

    #CVE-2026-7840 - #UltraVNC Repeater HTTP Global Buffer Overflow | Attribute | Value | |-----------|-------| | **CVE** | CVE-2026-7840 | | **CVSS** | 9.8 Critical (CVSS 3.1) | | **CWE** | CWE-121 — Stack-based Buffer Overflow | | **Vendor** | UltraVNC (UVNC BVBA) | | **Product** | UltraVNC Repeater | | **Affected** | <= 1.8.2.2 | | **Component** | `repeater/webgui/webutils.c` — `wi_senderr()`, `wi_replyhdr()` | | **Root Cause** | Unchecked `sprintf()` into 1000-byte global buffer `hdrbuf` | | **Trigger** | HTTP GET with URI length > 1000 bytes | | **Auth** | None — pre-authentication | #0days #exploit #cybersecurity #hacking #security #CVS #RCE #antisec #infosec

    Post summary

    The post announces a critical buffer overflow vulnerability in UltraVNC Repeater, detailing its technical aspects without referencing code, patches, or active exploits.

    0602481.5K
    1.9K followersView on X
  • Daily CyberSecurity@the_yellow_fall
    Disclosure

    Two UltraVNC repeater vulnerabilities enable arbitrary code execution (CVE-2026-7840) plus admin access via a hardcoded password. Update now. #UltraVNC #RemoteAccess #CVE20267839 #CVE20267840 #ArbitraryCodeExecution #BufferOverflow #Vulnerability http://securityonline.info/ultravnc-repeater-vulnerabilities-cve-2026-7840/

    Post summary

    The tweet announces that two UltraVNC repeater vulnerabilities allow arbitrary code execution and hardcoded admin access, urging users to update without detailing patches or active exploitation.

    03172780
    12.9K followersView on X
  • Lyrie.ai@lyrie_ai
    General

    | Attribute | Value | |-----------|-------| | CVE | CVE-2026-7840 | | CVSS | 9.8 Critical (CVSS 3.1) | | CWE | CWE-121 — Stack-based Buffer Overflow | | Vendor | UltraVNC (UVNC BVBA) | | Product

    Post summary

    The input provides core details of a high‑severity UltraVNC vulnerability but lacks any mention of PoC, exploit, patch, or active exploitation.

    1000036
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Value vs competitors: **CVE**: CVE-2026-7840 **CVSS**: 9.8 Critical (CVSS 3.1) **CWE**: CWE-121 — Stack-based Buffer Overflow 0day Intel: #CVE-2026-7840 - #UltraVNC Repeater HTTP Global Buffer Overflow

    Post summary

    The post announces a new critical CVE‑2026‑7840 affecting UltraVNC Repeater, detailing its stack‑based buffer overflow nature and high CVSS score, but it offers no exploit code, mitigation, or reports of active exploitation.

    1000041
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Source: X search for RCE 2026 exploit Posted: 2026-07-03T13:33:09.000Z Likes: 19 0day Intel: #CVE-2026-7840 - #UltraVNC Repeater HTTP Global Buffer Overflow

    Post summary

    The tweet announces the discovery of a 0day buffer overflow vulnerability in UltraVNC Repeater, but provides only the basic technical description without any PoC, exploit, or patch details.

    1000051
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-7840: #CVE-2026-7840 - #UltraVNC Repeater HTTP Global Buffer Overflow | Attribute | Value | |-----------|-------| | CVE | CVE-2026-7840 | | CVSS | 9.8 Critical (CVSS 3.1) | | CWE | CWE-121 — Stack-based Buffer Overflow | | Vendor | UltraVNC (UVNC BVBA) | | Product…

    Post summary

    A newly disclosed critical stack‑based buffer overflow (CVE‑2026‑7840) in UltraVNC Repeater is flagged with CVSS 9.8 and CWE‑121, but no PoC, exploit, patch, or active exploitation details are provided.

    1000048
    326 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appuvncultravnc---

Explore more