PatchSiren cyber security CVE debrief
CVE-2026-107611 GlavSoft CVE debrief
A vulnerability in TightVNC Viewer for Windows before 2.8.88 allows a malicious VNC server to crash the viewer by sending specially crafted ZRLE-encoded tiles. The vulnerability is due to an out-of-bounds read in the ZRLE decoder, which can lead to the viewer reading heap memory beyond the palette allocation. This can cause the viewer to crash or display garbled content. Defenders should be aware of the potential impact on their systems and take steps to mitigate the vulnerability. The vulnerability is caused by the readerPaletteRleTile() and readPackedPaletteTile() functions using the attacker-supplied index to look up colours without validating it against the palette size.
- Vendor
- GlavSoft
- Product
- TightVNC
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for managing and securing TightVNC Viewer for Windows installations should prioritize patching to version 2.8.88 or later to prevent potential crashes. This includes operators, platform administrators, vulnerability management teams, and security teams who need to ensure the security and stability of their systems.
Why it matters
Defenders should prioritize patching TightVNC Viewer for Windows to version 2.8.88 or later to prevent potential crashes due to an out-of-bounds read vulnerability in the ZRLE decoder.
- Potential crashes of the TightVNC Viewer
- Garbled display or read faults due to out-of-bounds heap data
Technical summary
The vulnerability is due to an out-of-bounds read in the ZRLE decoder of TightVNC Viewer for Windows before 2.8.88. A malicious VNC server can send ZRLE-encoded tiles with palette indices that exceed the declared palette size, causing the viewer to read heap memory beyond the palette allocation and crash. The vulnerability is caused by the readerPaletteRleTile() and readPackedPaletteTile() functions using the attacker-supplied index to look up colours without validating it against the palette size. This can lead to the viewer crashing or displaying garbled content.
Defensive priority
Defenders should prioritize patching TightVNC Viewer for Windows to version 2.8.88 or later to prevent potential crashes.
Recommended defensive actions
- Patch TightVNC Viewer for Windows to version 2.8.88 or later
- Restrict access to the TightVNC Viewer to trusted VNC servers only
- Monitor for potential crashes or anomalies in the TightVNC Viewer
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The vulnerability is described in the CVE record and the source item from the CVE Program. The affected version is TightVNC Viewer for Windows before 2.8.88. The CVE record was published on 2026-10-08T13:39:48.883Z and has not been modified since then. Additional information can be found in the official CVE Program record and the NIST NVD detail page.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107611 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107611
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107611 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107611
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Out-of-bounds read in TightVNC Viewer ZRLE palette decoding
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107611.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://sourceforge.net/p/vnc-tight/bugs/1657/
Supplemental source - issue-tracking
-
Source reference
Unverified legacy reference
URL: https://www.tightvnc.com/whatsnew.php
Supplemental source - release-notes, patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.