{"schema_version":1,"title":"UltraVNC vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 10 vulnerabilities in UltraVNC: 0 in the last 7 days and 10 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-7840, was published on 1 July 2026. 2 technologies have a page of their own.","url":"https://junglewise.ai/threats/vendors/ultravnc","json_url":"https://junglewise.ai/threats/vendors/ultravnc.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/ultravnc","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":4,"all_time":10,"critical":2,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":10,"last_365_days":10},"latest":[{"cve":"CVE-2026-7840","cvss":9.8,"slug":"cve-2026-7840-ultravnc-repeater-global-buffer-overflow-in-http-administration","title":"UltraVNC Repeater global buffer overflow in HTTP administration server","severity":"critical","exploited":false,"published_at":"2026-07-01T05:16:24.82+00:00","url":"https://junglewise.ai/threats/cve-2026-7840-ultravnc-repeater-global-buffer-overflow-in-http-administration"},{"cve":"CVE-2026-7839","cvss":9.1,"slug":"cve-2026-7839-ultravnc-repeater-hardcoded-password-in-http-administration-server","title":"UltraVNC Repeater hardcoded password in HTTP administration server","severity":"critical","exploited":false,"published_at":"2026-07-01T05:16:24.68+00:00","url":"https://junglewise.ai/threats/cve-2026-7839-ultravnc-repeater-hardcoded-password-in-http-administration-server"},{"cve":"CVE-2026-7838","cvss":8.8,"slug":"cve-2026-7838-ultravnc-viewer-heap-buffer-overflow-in-rfb-failure-response","title":"UltraVNC viewer heap buffer overflow in RFB failure-response parsing","severity":"high","exploited":false,"published_at":"2026-07-01T05:16:24.54+00:00","url":"https://junglewise.ai/threats/cve-2026-7838-ultravnc-viewer-heap-buffer-overflow-in-rfb-failure-response"},{"cve":"CVE-2026-7831","cvss":7.6,"slug":"cve-2026-7831-ultravnc-viewer-off-by-one-stack-buffer-overflow-in-rfb-handler","title":"UltraVNC Viewer off-by-one stack buffer overflow in RFB handler","severity":"high","exploited":false,"published_at":"2026-07-01T05:16:24.38+00:00","url":"https://junglewise.ai/threats/cve-2026-7831-ultravnc-viewer-off-by-one-stack-buffer-overflow-in-rfb-handler"},{"cve":"CVE-2026-7830","cvss":7.4,"slug":"cve-2026-7830-ultravnc-weak-cryptography-in-ms-logon-ii-authentication","title":"UltraVNC weak cryptography in MS-Logon II authentication","severity":"high","exploited":false,"published_at":"2026-07-01T05:16:24.21+00:00","url":"https://junglewise.ai/threats/cve-2026-7830-ultravnc-weak-cryptography-in-ms-logon-ii-authentication"},{"cve":"CVE-2026-7829","cvss":7.2,"slug":"cve-2026-7829-ultravnc-repeater-out-of-bounds-write-in-allow-deny-rule-parser","title":"UltraVNC Repeater out-of-bounds write in allow/deny rule parser","severity":"high","exploited":false,"published_at":"2026-07-01T05:16:24.087+00:00","url":"https://junglewise.ai/threats/cve-2026-7829-ultravnc-repeater-out-of-bounds-write-in-allow-deny-rule-parser"},{"cve":"CVE-2026-7828","cvss":5.3,"slug":"cve-2026-7828-ultravnc-repeater-integer-overflow-in-http-request-logging","title":"UltraVNC Repeater integer overflow in HTTP request logging","severity":"medium","exploited":false,"published_at":"2026-07-01T05:16:23.97+00:00","url":"https://junglewise.ai/threats/cve-2026-7828-ultravnc-repeater-integer-overflow-in-http-request-logging"},{"cve":"CVE-2026-44042","cvss":3.7,"slug":"cve-2026-44042-ultravnc-repeater-off-by-one-error-in-http-basic-authentication","title":"UltraVNC Repeater off-by-one error in HTTP Basic authentication","severity":"low","exploited":false,"published_at":"2026-07-01T05:16:21.153+00:00","url":"https://junglewise.ai/threats/cve-2026-44042-ultravnc-repeater-off-by-one-error-in-http-basic-authentication"},{"cve":"CVE-2026-44041","cvss":4.3,"slug":"cve-2026-44041-ultravnc-out-of-bounds-read-in-vncwc2mb-conversion-helper","title":"UltraVNC out-of-bounds read in vncWc2Mb conversion helper","severity":"medium","exploited":false,"published_at":"2026-07-01T05:16:21.033+00:00","url":"https://junglewise.ai/threats/cve-2026-44041-ultravnc-out-of-bounds-read-in-vncwc2mb-conversion-helper"},{"cve":"CVE-2026-44040","cvss":4.8,"slug":"cve-2026-44040-ultravnc-weak-prng-in-vnc-authentication-challenge","title":"UltraVNC weak PRNG in VNC authentication challenge","severity":"medium","exploited":false,"published_at":"2026-07-01T05:16:20.897+00:00","url":"https://junglewise.ai/threats/cve-2026-44040-ultravnc-weak-prng-in-vnc-authentication-challenge"}],"vendor":{"hub":true,"name":"UltraVNC","slug":"ultravnc","homepage":"https://uvnc.com/","description":"UltraVNC is a developer of open-source remote administration and desktop sharing software for Microsoft Windows.","url":"https://junglewise.ai/threats/vendors/ultravnc"},"weekly":[{"week":"2026-06-29","critical":2,"exploited":0,"vulnerabilities":10},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2026-7840","cvss":9.8,"slug":"cve-2026-7840-ultravnc-repeater-global-buffer-overflow-in-http-administration","title":"UltraVNC Repeater global buffer overflow in HTTP administration server","severity":"critical","exploited":false,"published_at":"2026-07-01T05:16:24.82+00:00","url":"https://junglewise.ai/threats/cve-2026-7840-ultravnc-repeater-global-buffer-overflow-in-http-administration"},{"cve":"CVE-2026-7839","cvss":9.1,"slug":"cve-2026-7839-ultravnc-repeater-hardcoded-password-in-http-administration-server","title":"UltraVNC Repeater hardcoded password in HTTP administration server","severity":"critical","exploited":false,"published_at":"2026-07-01T05:16:24.68+00:00","url":"https://junglewise.ai/threats/cve-2026-7839-ultravnc-repeater-hardcoded-password-in-http-administration-server"},{"cve":"CVE-2026-7838","cvss":8.8,"slug":"cve-2026-7838-ultravnc-viewer-heap-buffer-overflow-in-rfb-failure-response","title":"UltraVNC viewer heap buffer overflow in RFB failure-response parsing","severity":"high","exploited":false,"published_at":"2026-07-01T05:16:24.54+00:00","url":"https://junglewise.ai/threats/cve-2026-7838-ultravnc-viewer-heap-buffer-overflow-in-rfb-failure-response"},{"cve":"CVE-2026-7831","cvss":7.6,"slug":"cve-2026-7831-ultravnc-viewer-off-by-one-stack-buffer-overflow-in-rfb-handler","title":"UltraVNC Viewer off-by-one stack buffer overflow in RFB handler","severity":"high","exploited":false,"published_at":"2026-07-01T05:16:24.38+00:00","url":"https://junglewise.ai/threats/cve-2026-7831-ultravnc-viewer-off-by-one-stack-buffer-overflow-in-rfb-handler"},{"cve":"CVE-2026-7830","cvss":7.4,"slug":"cve-2026-7830-ultravnc-weak-cryptography-in-ms-logon-ii-authentication","title":"UltraVNC weak cryptography in MS-Logon II authentication","severity":"high","exploited":false,"published_at":"2026-07-01T05:16:24.21+00:00","url":"https://junglewise.ai/threats/cve-2026-7830-ultravnc-weak-cryptography-in-ms-logon-ii-authentication"},{"cve":"CVE-2026-7829","cvss":7.2,"slug":"cve-2026-7829-ultravnc-repeater-out-of-bounds-write-in-allow-deny-rule-parser","title":"UltraVNC Repeater out-of-bounds write in allow/deny rule parser","severity":"high","exploited":false,"published_at":"2026-07-01T05:16:24.087+00:00","url":"https://junglewise.ai/threats/cve-2026-7829-ultravnc-repeater-out-of-bounds-write-in-allow-deny-rule-parser"},{"cve":"CVE-2026-7828","cvss":5.3,"slug":"cve-2026-7828-ultravnc-repeater-integer-overflow-in-http-request-logging","title":"UltraVNC Repeater integer overflow in HTTP request logging","severity":"medium","exploited":false,"published_at":"2026-07-01T05:16:23.97+00:00","url":"https://junglewise.ai/threats/cve-2026-7828-ultravnc-repeater-integer-overflow-in-http-request-logging"},{"cve":"CVE-2026-44040","cvss":4.8,"slug":"cve-2026-44040-ultravnc-weak-prng-in-vnc-authentication-challenge","title":"UltraVNC weak PRNG in VNC authentication challenge","severity":"medium","exploited":false,"published_at":"2026-07-01T05:16:20.897+00:00","url":"https://junglewise.ai/threats/cve-2026-44040-ultravnc-weak-prng-in-vnc-authentication-challenge"},{"cve":"CVE-2026-44041","cvss":4.3,"slug":"cve-2026-44041-ultravnc-out-of-bounds-read-in-vncwc2mb-conversion-helper","title":"UltraVNC out-of-bounds read in vncWc2Mb conversion helper","severity":"medium","exploited":false,"published_at":"2026-07-01T05:16:21.033+00:00","url":"https://junglewise.ai/threats/cve-2026-44041-ultravnc-out-of-bounds-read-in-vncwc2mb-conversion-helper"},{"cve":"CVE-2026-44042","cvss":3.7,"slug":"cve-2026-44042-ultravnc-repeater-off-by-one-error-in-http-basic-authentication","title":"UltraVNC Repeater off-by-one error in HTTP Basic authentication","severity":"low","exploited":false,"published_at":"2026-07-01T05:16:21.153+00:00","url":"https://junglewise.ai/threats/cve-2026-44042-ultravnc-repeater-off-by-one-error-in-http-basic-authentication"}],"generated_at":"2026-09-26T09:11:00.170868+00:00","technologies":[{"name":"UltraVNC Repeater","slug":"repeater","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/repeater"},{"name":"UltraVNC","slug":"ultravnc","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/ultravnc"}]}