A working exploit called AnyPwn has been reported for a pre-authentication flaw in AnyDesk for Linux. The exploit targets version 8.0.2 and can execute an attacker-supplied command as root over a direct TCP connection on port 7070. The report identifies AnyDesk Linux 8.0.3 as the fixed release; AnyDesk’s Linux changelog listed 8.1.0 as the latest version on October 9, 2026. Administrators should update to a current supported release. If they cannot update promptly, restrict access to TCP 7070 as an interim measure.
What the reported flaw allows
According to The Hacker News report published October 9, 2026, the vulnerability is a heap buffer overflow in AnyDesk’s Linux session protocol. It can allow code execution before a remote connection is approved, with the demonstrated exploit running a command as root.
As an Amazon Associate I earn from qualifying purchases.
The publicly released exploit’s offsets target AnyDesk Linux 8.0.2. The report says earlier versions may share the vulnerable code path, but does not confirm that they can be exploited. Do not treat every older build as a verified target.
Recommended Free Tools
How the exploit reportedly works
The report describes a flaw in handling mode-5 stream packets. The handler adds a 16-byte header to the declared payload length using 32-bit arithmetic without checking for overflow. A declared length of 0xFFFFFFF0 plus 0x10 wraps to zero, leading to an allocation smaller than the packet data requires. A subsequent write can go beyond that allocation into neighboring heap objects.
#1 Best Overall
- Powerful Linux Laptop: This IdeaPad Slim 3 Laptop comes pre-installed with Ubuntu Linux, offering fast performance, robust security, and a clean, user-friendly experience. Enjoy full customization, seamless hardware compatibility, and access to thousands of open-source apps. Whether you're working, creating, or coding, it's built to keep up with everything you do.
- A Multitasking Master: The latest AMD Ryzen 7 5825U processor (up to 4.5 GHz) delivers powerful performance with 8 cores and 16 threads for smooth multitasking. Integrated AMD Radeon Graphics provide crisp visuals for streaming, browsing, photo editing, and casual gaming. With smart machine intelligence, it adapts to your needs for a fast, responsive experience.
- 15.6" Full HD Display: The IdeaPad Slim 3 boasts an 88% screen-to-body ratio for a floating, edge-to-edge visual experience. TÜV Low Blue Light certification reduces eye strain, making it perfect for long work or study sessions.
- Military-Grade Durability: The smart IdeaPad Slim 3 combines portability and durability, letting you work, study, and play on the go. With a profile 10% slimmer than the previous generation, it's lightweight yet military-grade rugged, ready for anything, anywhere.
- Versatile Connectivity: Enjoy the security of a built-in webcam with a privacy shutter. Connect effortlessly with multiple ports: 2x USB A, 1x USB C, 1x HDMI, 1x SD Card Reader, 1x Headphone/Microphone combo. Bundle comes with Stylus Pen, 256GB Portable SSD and 5-in-1 Docking Station.
The researchers’ exploit reportedly corrupts adjacent object fields and uses a return-oriented programming (ROP) chain to execute a command as root. The demonstration is probabilistic: an unfavorable heap layout can make the service crash instead of executing the command. These mechanics are attributed to the report and researchers; the exploit repository was not independently reviewed for this account.
Which connections and systems are in scope
Direct Linux connections
The demonstrated exploit works over a direct TCP connection on port 7070. AnyDesk’s statement, quoted through The Hacker News, says the vulnerability is “limited to direct connections on Linux (connections that do not go through our relays). Windows and macOS are not affected.” The report does not identify a named spokesperson for that statement.
Rank #2
- Intel Core i5-10210U (up to 4.2GHz) - 1TB PCIe NVMe + 1TB HDD - 32GB DDR4 SDRAM
- 17.3" HD+ (1600x900) Display, Intel UHD Graphics 620
- Built in HD 720p Webcam with Microphone - Bluetooth Version4.2
- I/O Ports: 2x USB 3.1 (Data Only), 1x USB 2.0, 1x HDMI, 1x Headphone/Microphone Combo Jack
- Linux Mint Cinnamon 64-Bit - 6-Row Keyboard w/ Full Numberpad
Relay connections remain unresolved
The researchers reportedly triggered the vulnerable code path through relay servers, but did not demonstrate the complete exploit chain through a relay. That leaves a distinction between reaching the path and proving successful exploitation via relay; the report does not establish the latter.
Which versions need attention
The exploit targets Linux 8.0.2. The report identifies 8.0.3 as patched, and AnyDesk’s changelog records these release dates and notes:
Rank #3
- Intel Core i5-1335U Processor (12M Cache, 12 Threads, up to 4.6 GHz) - 256GB Solid State Drive - 16GB DDR4 SDRAM
- 15.6" FHD (1920x1080) Non-Touch Anti-Glare Display - Intel UHD 620 Integrated Graphics - Stereo Speakers
- 720p HD Webcam with Privacy Shutter. Integrated Microphone - Intel Dual Band Wireless-AC (2x2) 8265, Bluetooth Version 4.2
- I/O Ports: 2x USB 3.0, 1x USB 3.1 Type-C 3.1, Headphone/Mic Combo Port, 4-in-1 Card Reader, HDMI, Kensington Mini-Lock Slot
- Linux Mint (Cinnamon) 64-Bit - Keyboard with Full NumberPad - Fast Charging
| AnyDesk Linux version | Changelog date | Relevant detail |
|---|---|---|
| 8.0.2 | April 1, 2026 | Targeted by the public exploit, according to The Hacker News. |
| 8.0.3 | June 23, 2026 | Changelog says: “Fixed a bug that could lead to a crash.” The report identifies this as the fixed release. |
| 8.0.4 | June 30, 2026 | Later release listed in the changelog. |
| 8.1.0 | September 23, 2026 | Latest release listed in the changelog as of October 9, 2026. |
The 8.0.3 changelog wording does not label the change a security fix. The release history is available in AnyDesk’s official Linux changelog. Version availability can change; the 8.1.0 latest-version observation is specific to October 9, 2026.
What Linux administrators should do
- Check installed versions. Identify every Linux host running AnyDesk, then verify its installed version using the package manager or deployment inventory appropriate to that system.
- Update. Install at least 8.0.3, the release the report identifies as patched. Prefer the current supported AnyDesk Linux release available from AnyDesk rather than treating 8.0.3 as a timeless recommendation.
- If an update is delayed, restrict TCP 7070. Limit inbound access to the port at the host firewall or network boundary to trusted sources, or block it where direct connections are not required. Confirm the rule matches the actual exposure in your deployment; the report gives no firewall-specific commands.
- Review exposure and service health. Prioritize systems reachable over direct TCP 7070 and check for unexpected AnyDesk service crashes. A crash can be a failed exploit attempt, but the report does not establish that crashes alone indicate an attack.
Restricting the port is an interim reduction in exposure, not a substitute for installing the fixed release.
Rank #4
Disclosure and advisory status
The Hacker News credits discovery to Rick de Jager of the V12 security team and says the team announced the flaw on June 22, 2026. The report says AnyDesk acknowledged it the following day and released 8.0.3 on June 23; the public exploit appeared on GitHub on October 8.
As of the report’s October 9, 2026 publication, no CVE had been assigned and AnyDesk had not published a formal security advisory. The available changelog entry is the crash-related wording shown above, rather than a detailed security notice.
Quick Recap
Best Value
- 12th Intel Alder Lake N95 Processor – The GMKtec G3 S Mini PC is powered by the 12th Gen Intel N95 processor with 4 cores, 4 threads, 6MB cache and a burst frequency up to 3.4GHz. Compared with N100/N5105/N5100/N5095, the N95 delivers up to 36% overall performance improvement. Perfect for routine tasks, office work, and home entertainment, this compact mini desktop is more convenient than traditional bulky PCs.
- 8GB RAM & 256GB SSD Storage – Pre-installed with 8GB DDR4 memory and a fast 256GB M.2 2242 SSD, the G3 S mini desktop offers quicker startup, smoother multitasking, and faster file transfers. Enjoy seamless performance whether you’re working on multiple applications, browsing, or streaming content.
- Rich Interfaces & Connectivity – The G3 S mini computer comes equipped with USB 3.2 (up to 10Gbps), dual HDMI 2.0 (4K@60Hz), and a 3.5mm audio jack. With support for WiFi 5, Bluetooth 5.0, and Gigabit Ethernet (RJ45 1000MbE), it connects easily with monitors, projectors, printers, office equipment, and other peripherals, making it versatile for both home and business use.
- Dual 4K Display Support – Featuring upgraded Intel UHD Graphics (up to 1000MHz), the G3 S supports 4K video playback and AV1 decoding for a smooth viewing experience. With dual HDMI outputs, you can connect two 4K@60Hz displays simultaneously, enabling efficient multitasking for work and entertainment.
- GMKTEC WARRANTY - GMKtec offers a 3-year limited warranty (1 year replacement + 2 years parts replacement) for each mini PC, starting from the date of the purchase effective on all sales starting Oct. 2026. All defects due to design and workmanship are covered. With a professional after sales team always ready to attend to your needs, you can simply relax and enjoy your mini PC
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




