Junglewise Threat Intelligence

CVE-2026-68960: Sky SKYSEA Client View stack-based buffer overflow

CVE-2026-68960 · Severity: high · CVSS 8.5 · Published 2026-08-25

Technologies: Skymec It Manager, Skysea Client View.

Executive brief

SKYSEA Client View is an IT client management and monitoring system deployed across Windows workstations. A stack-based buffer overflow in the product allows an attacker who has logged into one Windows computer to remotely execute arbitrary code on other computers running the product via crafted UDP packets, potentially compromising enterprise endpoints without additional authentication.

Technical details

CVE-2026-68960 is a stack-based buffer overflow (CWE-121) in SKYSEA Client View and SKYMEC IT Manager. An attacker with login credentials to a Windows system running the affected product can send specially crafted UDP packets to another system with the product installed, causing a buffer overflow that leads to arbitrary code execution. The vulnerability requires the attacker to be authenticated on the source system and the target system to be network-reachable and able to receive UDP packets from the source. Sky Co., Ltd. has released patched versions (SKYSEA Client View Ver. 21.310.01a and later, SKYMEC IT Manager with correction modules) to remediate the issue.

Affected products

  • Sky SKYSEA Client View Ver. 21.210.01f and earlier
  • Sky SKYMEC IT Manager Ver. 2023.225.03a and Ver. 2024.005.10a

Timeline

  • 2026-08-24: disclosed
  • 2026-08-24: patched: Patch modules released for both SKYSEA Client View and SKYMEC IT Manager

References