AnyDesk Root Exploit, SonicWall SMA1000 Attacks, and a Critical NetScaler Flaw

A public AnyDesk Linux exploit grants root access, attackers are probing a CVSS 10.0 SonicWall SMA1000 flaw, one small request can freeze React Server Components apps, CastleStealer adds a remote shell, and a critical NetScaler bug threatens SAML-enabled appliances.

AnyDesk Root Exploit, SonicWall SMA1000 Attacks, and a Critical NetScaler Flaw

Public AnyPwn Exploit Gives Attackers Root on AnyDesk Linux

AnyDesk quietly patched a heap overflow in its Linux client back in June. Now there’s a working public exploit, and it takes over unpatched hosts before anyone approves a connection.

What You Need to Know

Researchers have released AnyPwn, a working exploit that gets pre-authentication remote code execution as root on AnyDesk Linux 8.0.2. AnyDesk fixed the flaw in 8.0.3, but nothing in the release notes flagged it as a security issue. If any of your Linux systems still run a vulnerable build, upgrade them now.

What Happened

Security researchers published AnyPwn on October 8. It targets a heap buffer overflow in AnyDesk’s session protocol, and the user never has to approve the incoming connection. When AnyDesk shipped the fix in June 2026, the changelog described it only as a bug that could cause a crash. The company never published a security advisory, and no CVE had been assigned as of October 9. The public code is written specifically for AnyDesk Linux 8.0.2, so it’s now much easier for attackers to reproduce the attack.

The Details

The bug is in how the session protocol sizes a memory allocation. It adds a 16-byte header to a payload length the attacker controls, using unchecked 32-bit arithmetic. AnyPwn sends a payload length of 0xFFFFFFF0, so adding 0x10 wraps the allocation size around to zero. The application allocates a small buffer but keeps using the original, much larger length, and attacker-controlled data overwrites the heap objects next to it. From there, the exploit corrupts object fields and uses a return-oriented programming chain to run any command as root. The published exploit uses offsets specific to 8.0.2 and currently works over direct TCP connections on port 7070. AnyDesk says the vulnerability is limited to direct Linux connections and doesn’t affect Windows or macOS.

Why This Matters

A fix labeled as a crash bug is easy to push down the patch queue, so many Linux hosts may still be on 8.0.2 months after 8.0.3 shipped. Exploitation doesn’t work every time. The targeted object has to land next to the vulnerable buffer, and a failed attempt may just crash the AnyDesk service. But nothing stops an attacker from trying again, and a run of service crashes may be the first sign anyone notices. Researchers have also reached the vulnerable code path through AnyDesk’s relay infrastructure using instrumentation, though they haven’t shown the full exploit chain working through a relay. Until that’s settled, blocking port 7070 on its own isn’t full protection.

What to Do

Find every Linux system running AnyDesk and upgrade it to 8.0.3 or later (8.1.0 is the latest release). If you can’t patch right away, restrict inbound access to TCP port 7070 and block direct connections from untrusted networks that don’t need them. Check network and endpoint telemetry for unexpected traffic to port 7070, repeated AnyDesk service crashes, abnormal child processes, and commands run by the AnyDesk service account. Nobody has settled yet whether the relay path can be exploited reliably, so treat patching as the fix and network filtering as a stopgap.


Attackers Are Probing a CVSS 10.0 SonicWall SMA1000 Flaw

Exploitation attempts against SonicWall’s SMA1000 secure remote access appliances started soon after a maximum-severity flaw was patched. This post covers the affected builds, the attack traffic seen so far, and the versions that fix it.

What You Need to Know

Attackers are trying to exploit CVE-2026-102255, a pre-authentication server-side request forgery (SSRF) flaw in SonicWall SMA1000 appliances with a CVSS score of 10.0. The attempts began shortly after SonicWall released patches. There’s no workaround, so installing the correct platform hotfix is the only fix.

What’s Vulnerable

CVE-2026-102255 can be reached before authentication through the Appliance WorkPlace interface. A remote attacker abuses an unintended alternate access path to make the appliance send requests to internal services and carry out unauthorized operations. The flaw affects SMA 6210, 7210, and 8200v appliances running platform-hotfix 12.4.3-03526 or earlier, or 12.5.0-02952 or earlier. SonicWall firewalls running SSL-VPN aren’t affected, and neither is the discontinued SMA 100 Series.

What Happened

Previdian’s honeypot network picked up activity consistent with attempted exploitation shortly after the patches came out. The requests targeted the WorkPlace Extraweb interface. They used a crafted HTTP OPTIONS request to reach the appliance’s internal CouchDB service at 127.0.0.1:5984. The payload tried to traverse into a CouchDB design document, call its _rewrite function, and log in with admin:admin. The SSRF vulnerabilities disclosed in July and September 2026 hit this same WorkPlace interface, but this activity uses a different technique.

Why This Matters

SMA1000 gateways sit in front of internal applications and networks. An attacker who compromises one has a foothold for credential theft, lateral movement, persistence, or follow-on ransomware. The WorkPlace interface has now been the subject of three SSRF disclosures since July, so attackers already know where to look. How much damage has actually been done is still unclear. Researchers haven’t confirmed that any of the observed attempts compromised a system. The more than 400 SMA1000 appliances reportedly exposed to the internet may include honeypots and systems already running patched firmware.

What to Do

Upgrade affected appliances to platform-hotfix 12.4.3-03670 or later, or 12.5.0-03082 or later. Check the complete firmware build, not just the major release number. Builds installed to fix the earlier vulnerabilities may still be affected by this one. In your logs, look for unusual OPTIONS requests to the WorkPlace Extraweb interface, attempts to reach 127.0.0.1:5984, references to CouchDB design documents or _rewrite, and Basic Authorization headers containing admin:admin. If operations allow it, restrict public access to the WorkPlace interface and limit which internal services the appliance can talk to. Investigate any unexpected configuration changes or authentication activity.


One Small Request Can Stall React Server Components Apps

A denial-of-service flaw in React Server Components lets an unauthenticated attacker tie up a Node.js server with a single request under a megabyte. Next.js apps built on the App Router are in scope.

What You Need to Know

CVE-2026-23870 is a high-severity denial-of-service vulnerability (CVSS 7.5) in the React Server Components packages used by React 19. A crafted request of about 900 KB can lock up a server’s processing before any authentication check runs. Meta has released fixed versions. Affected applications need to be rebuilt and redeployed to pick them up.

What’s Vulnerable

CVE-2026-23870 affects react-server-dom-webpack, react-server-dom-turbopack, and react-server-dom-parcel in React 19.0.0 through 19.0.5, 19.1.0 through 19.1.6, and 19.2.0 through 19.2.5. Frameworks that rely on these packages may also be exposed, including Next.js deployments using the App Router and Server Actions. Your application isn’t affected if it doesn’t use a server, or doesn’t use a framework, bundler, or plugin that supports React Server Components.

How the Attack Works

The problem is in how React rebuilds multipart form data submitted to Server Action endpoints. An attacker can pack a request with $K references, which tell React to resolve embedded or nested form-data structures. For each reference, the vulnerable code builds and searches a complete list of submitted fields, so processing grows quadratically. A request with 10,000 references and 10,000 filler fields can trigger about 100 million string comparisons while staying around 900 KB. Node.js typically runs JavaScript on a single event-loop thread, so unrelated requests wait while that parsing runs. Pages, APIs, and Server Actions stall or time out. The same request can also drive memory use high enough to crash the server outright. The Server Action identifier the attacker needs can be pulled from the rendered HTML or JavaScript assets of a public page.

Why This Matters

Parsing happens before application-level authorization, so authentication, CSRF protections, and action-specific access controls never get a chance to stop it. The attacker doesn’t need an account, just a public page to pull a target from. Because the request is small relative to the work it causes, standard request-size limits are unlikely to catch it. A single attacker with modest bandwidth can keep a production app unavailable.

What to Do

Upgrade to React 19.0.6, 19.1.7, or 19.2.6. The corrected parser uses shared traversal instead of restarting a full field scan for every nested reference, which removes the repeated processing behind the CPU spike. Check package manifests, lockfiles, build artifacts, and deployed containers for affected React Server Components dependencies. A new version number in the manifest doesn’t help if production is still running the old build, so rebuild and redeploy after upgrading. Watch Server Action routes for unusual multipart POST requests, large numbers of form fields, repeated nested references, CPU saturation, event-loop delays, memory pressure, and unexplained application restarts. Request-size limits and rate controls may reduce some exposure, but they aren’t a substitute for patching.


CastleStealer Grows from Infostealer into Remote Access Tool

New CastleStealer samples go well past password theft. The malware can now run remote commands, deliver more payloads, and get around Chrome’s newest browser data protections.

What You Need to Know

CastleStealer is a C# information stealer first identified in April 2026. According to Flashpoint, newer samples can bypass Chromium app-bound encryption (ABE), run commands remotely, deploy additional payloads, and exfiltrate data in small encrypted TCP transmissions. That means an infection that starts as credential theft can turn into interactive access and follow-on compromise.

How It Spreads

Early CastleStealer campaigns used ClickFix social engineering to deliver a Python script that launched CastleLoader. By June, the operators had added a malvertising campaign: users searching for Node.js were redirected to fraudulent installation sites, where a batch script posing as an installer downloaded OXLOADER. This custom loader uses layered decryption, obfuscated API resolution, sandbox checks, and in-memory execution to make detection and analysis harder.

What It Does Now

Once it’s running, CastleStealer checks whether the system language is set to Russian before contacting its command-and-control infrastructure. It sends a handshake with its build identifier and basic host information, followed by more detailed system data.

In Chromium browsers, it targets saved credentials, cookies, browsing history, web data, and extension storage, including IndexedDB databases that may hold cryptocurrency wallet information. It also collects Firefox credentials and browser artifacts, Steam configuration files, and data tied to Discord and Telegram. Its file harvesting prioritizes filenames containing “wallet” and skips selected file types and any names containing “backup.”

Earlier versions relied on traditional data-protection mechanisms and couldn’t read data protected by Chromium ABE. Newer samples get around this through Chrome’s IElevator COM interface, which restores access to protected browser data under some configurations. The malware also now includes a basic remote shell that lets operators submit commands, provide files to execute, or have it download and launch additional payloads.

Stolen data leaves over raw TCP with AES-128 CBC encryption. Each packet contains a four-byte size field, an initialization vector, and the encrypted content. Rather than sending one large archive, CastleStealer splits the data across smaller exchanges. Afterward, it deletes itself using a ping-delay technique.

Why This Matters

With a remote shell, a CastleStealer infection can progress from automated data theft to interactive system access, follow-on malware deployment, and persistent compromise. Splitting exfiltration into small chunks keeps network-volume changes small, so volume-based alerting may miss it. The Node.js lure goes after developers, whose machines tend to hold valuable credentials. Flashpoint hasn’t observed widespread adoption yet. But the steady development and increasingly sophisticated loaders show the operators are working on both evasion and new capabilities.

What to Do

Watch for suspicious Node.js download ads, batch scripts retrieving executables, unexpected PowerShell activity, anomalous in-memory .NET execution, raw encrypted TCP sessions, Chrome IElevator access from non-browser processes, and collection of browser or messaging app data. Block fraudulent software distribution channels and point users to official download sources. Tighten behavioral endpoint detections as well, because CastleStealer’s operators keep refining both how it gets in and what it does once it’s there.


Critical NetScaler Flaw Puts SAML Deployments at Risk

Citrix has patched a critical memory overflow in customer-managed NetScaler ADC and Gateway appliances. Whether you’re exposed depends on your build number and SAML role.

What You Need to Know

CVE-2026-107406 is a critical memory overflow in NetScaler ADC and NetScaler Gateway, scored 9.5 under CVSS v4.0, that can lead to remote code execution or denial of service. Depending on the build, the appliance has to be configured as a SAML identity provider or service provider to be exploitable. Attackers have a track record of going after NetScaler, so put affected appliances at the top of the patch list.

What’s Vulnerable

CVE-2026-107406 affects customer-managed NetScaler ADC and Gateway appliances that use Security Assertion Markup Language (SAML) as an identity provider (IdP) or service provider (SP). Versions earlier than 14.1-73.37 or 13.1-64.23 are affected when configured as either a SAML SP or IdP. Builds 14.1-73.37 through 14.1-73.41 and 13.1-64.23 through 13.1-64.28 are affected only when configured as a SAML IdP. Equivalent conditions apply to affected FIPS and NDcPP releases. Secure Private Access Hybrid deployments using NetScaler instances are also affected. Citrix-managed cloud services are not.

Why This Matters

Citrix hadn’t identified any unmitigated exploitation of CVE-2026-107406 when it published the bulletin, but that doesn’t make it low risk. NetScaler appliances are internet-facing and control access to authentication services, applications, and internal networks. Shadowserver counted more than 21,000 internet-exposed systems with NetScaler fingerprints, including about 1,500 Gateway instances and nearly 20,000 ADC appliances. That count doesn’t show how many are vulnerable, configured in an exploitable way, patched, or running as honeypots. Even so, that much exposure makes it likely attackers will scan for affected builds and analyze the flaw. Earlier in 2026, attackers exploited other Citrix vulnerabilities to deploy web shells and tunneling tools, steal credentials, gain root access, and move into internal environments.

What to Do

Upgrade NetScaler ADC and Gateway to 14.1-73.46 or later, or 13.1-64.29 or later on the 13.1 branch. NetScaler ADC 14.1-FIPS requires 14.1-73.46 FIPS or later, and 13.1-FIPS and 13.1-NDcPP deployments require 13.1-37.283 or later. Inventory your customer-managed appliances, record complete build numbers, and confirm whether each one acts as a SAML SP, SAML IdP, or both. In the configuration, add authentication samlAction indicates SAML SP use and add authentication samlIdPProfile indicates a SAML IdP. Review appliances for unexpected processes, configuration changes, crashes, web shells, outbound tunnels, credential access, and suspicious authentication activity. Exploitation could give an attacker control of an access gateway, so patch affected systems first and validate them after the update.

💡
That's this week's threat landscape from Hunter Strategy, brought to you by William Elchert.
Our Threat Intelligence Team monitors emerging vulnerabilities and adversary activity, like what's covered in these articles, across federal and commercial environments. To learn how our Managed Security Services can help protect your organization, visit our Managed Security Services page.