PatchSiren

AnyDesk CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM AnyDesk CVE published 2026-07-13

CVE-2026-15682

CVE-2026-15682 is a denial-of-service vulnerability in AnyDesk's support information feature. Local attackers with low-privileged code execution can exploit it by creating a junction to create arbitrary files, leading to a denial-of-service condition. This vulnerability requires an attacker to first obtain the ability to execute low-privileged code on the target system. Users should be aware of the potent [truncated]

MEDIUM AnyDesk CVE published 2026-07-13

CVE-2026-15681

CVE-2026-15681 is a medium-severity vulnerability in AnyDesk that allows local attackers to create a denial-of-service condition. To exploit this vulnerability, an attacker must first obtain the ability to execute low-privileged code on the target system. The flaw exists within the handling of screen recording files, where an attacker can create a junction to abuse the service and create arbitrary files, [truncated]

HIGH Anydesk CVE published 2026-06-19

CVE-2016-20094

CVE-2016-20094 is a HIGH-severity vulnerability (CVSS Score: 8.5) affecting AnyDesk 2.5.0. The issue is an unquoted service path vulnerability, which allows local users to execute arbitrary code with SYSTEM privileges by inserting malicious executables in the system root path. This can occur during application startup or system reboot. Defenders should prioritize patching or mitigating this vulnerability [truncated]