AnyDesk's vulnerability profile concentrates in its single remote-access and desktop-sharing application, a tool with direct exposure to authentication and access-control boundaries and thus elevated potential for lateral movement and unauthorized session hijacking. The vendor's disclosures skew toward serious outcomes, with a meaningful tendency toward critical severity and public exploit availability, driven by recurring weaknesses in link resolution, authentication bypass, and access control that directly undermine the security model of remote-session tools. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Anydesk over time
Signals from CVEs in this vendor scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-13160CRITICAL AnyDesk before 5.5.3 on Linux and FreeBSD has a format string vulnerability that can be exploited for remote code execution. | Jun 9, 2020 | 9.8 | 84 | NO | YES |
CVE-2016-20094HIGH AnyDesk 2.5.0 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with SYSTEM privileges by exploiting the service installation. Attac | Jun 19, 2026 | 7.8 | 33 | NO | NO |
CVE-2026-15682MEDIUM AnyDesk Support Information Link Following Denial-of-Service Vulnerability. This vulnerability allows local attackers to create a denial-of-service condition on affected installati | Jul 13, 2026 | 5.5 | 31 | NO | NO |
CVE-2025-27918CRITICAL An issue was discovered in AnyDesk for Windows before 9.0.5, AnyDesk for macOS before 9.0.1, AnyDesk for Linux before 7.0.0, AnyDesk for iOS before 7.1.2, and AnyDesk for Android b | Nov 6, 2025 | 9.8 | 29 | NO | NO |
CVE-2017-14397CRITICAL AnyDesk before 3.6.1 on Windows has a DLL injection vulnerability. | Sep 12, 2017 | 9.8 | 29 | NO | NO |
CVE-2026-15681MEDIUM AnyDesk Screen Recording Link Following Denial-of-Service Vulnerability. This vulnerability allows local attackers to create a denial-of-service condition on affected installations | Jul 13, 2026 | 5.5 | 28 | NO | NO |
CVE-2021-44426HIGH An issue was discovered in AnyDesk before 6.2.6 and 6.3.x before 6.3.5. An upload of an arbitrary file to a victim's local ~/Downloads/ directory is possible if the victim is using | Sep 12, 2022 | 8.8 | 28 | NO | NO |
CVE-2025-27919HIGH An issue was discovered in AnyDesk through 9.0.4. A remotely connected user with the "Control my device" permission can manipulate remote AnyDesk settings and create a password for | Nov 6, 2025 | 8.2 | 25 | NO | NO |
CVE-2022-32450HIGH AnyDesk 7.0.9 allows a local user to gain SYSTEM privileges via a symbolic link because the user can write to their own %APPDATA% folder (used for ad.trace and chat) but the produc | Jul 18, 2022 | 7.1 | 25 | NO | NO |
CVE-2021-40854HIGH AnyDesk before 6.2.6 and 6.3.x before 6.3.3 allows a local user to obtain administrator privileges by using the Open Chat Log feature to launch a privileged Notepad process that ca | Oct 14, 2021 | 7.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (19 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Anydesk.
Media articles that mention a CVE ID that affects a product developed by Anydesk — matched by CVE ID, not by vendor name.