Patch & vulnerability status
GlavSoft LLC.
TightVNC 2.8.88
Latest tracked version 2.8.88. Release status, tracked CVEs, and automated cross-platform patching for TightVNC.
| Platform | Latest version | CVEs tracked | Last checked |
|---|---|---|---|
| Windows | 2.8.88 | 6 | 2026-08-10 |
Known vulnerabilities (CVEs) in TightVNC
Lavawall tracks 6 published CVEs affecting TightVNC, and deploys the versions that fix them automatically across your fleet.
| CVE | Published | Severity | Details | Vector |
|---|---|---|---|---|
| CVE-2023-27830 | 2023-04-12 15:15:13 | CRITICAL (9) | TightVNC before v2.8.75 allows attackers to escalate privileges on the host operating system via replacing legitimate files with crafted files when executing a file transfer. This is due to the fact that TightVNC runs in the backend as a high-privileges account. | NETWORK |
| CVE-2021-42785 | 2021-11-23 22:15:08 | CRITICAL (10) | Buffer Overflow vulnerability in tvnviewer.exe of TightVNC Viewer allows a remote attacker to execute arbitrary instructions via a crafted FramebufferUpdate packet from a VNC server. | NETWORK |
| CVE-2019-8287 | 2019-10-29 19:15:23 | CRITICAL (10) | TightVNC code version 1.3.10 contains global buffer overflow in HandleCoRREBBP macro function, which can potentially result code execution. This attack appear to be exploitable via network connectivity. | NETWORK |
| CVE-2019-15680 | 2019-10-29 19:15:18 | HIGH (8) | TightVNC code version 1.3.10 contains null pointer dereference in HandleZlibBPP function, which results Denial of System (DoS). This attack appear to be exploitable via network connectivity. | NETWORK |
| CVE-2019-15679 | 2019-10-29 19:15:18 | CRITICAL (10) | TightVNC code version 1.3.10 contains heap buffer overflow in InitialiseRFBConnection function, which can potentially result code execution. This attack appear to be exploitable via network connectivity. | NETWORK |
| CVE-2019-15678 | 2019-10-29 19:15:18 | CRITICAL (10) | TightVNC code version 1.3.10 contains heap buffer overflow in rfbServerCutText handler, which can potentially result code execution.. This attack appear to be exploitable via network connectivity. | NETWORK |
Why keeping TightVNC patched matters
Unpatched third-party applications are one of the most common ways attackers get in: 57% of breached MSP clients and 32% of ransomware cases trace back to a missing patch. Every TightVNC release that fixes a security bug is public, so attackers see it too, and an out-of-date install becomes a documented way in. Tracking the installed version on every machine and closing the gap quickly is what turns a disclosed CVE into a non-event.
How Lavawall® patches TightVNC
Lavawall® watches TightVNC releases and CVEs continuously, ranks each update by risk, and deploys it across your whole fleet, Windows, macOS, and Linux, from a single agent, independently of your RMM. You get one place to see which machines are behind on TightVNC, one policy to bring them current, and timestamped evidence for audits.
Frequently asked questions
Lavawall tracks TightVNC at version 2.8.88 (last checked 2026-08-10). New releases are monitored continuously and can be deployed automatically across your fleet.
Lavawall tracks 6 CVEs for TightVNC and remediates them automatically as part of patching.
Deploy the Lavawall® agent and TightVNC updates are applied automatically across Windows, macOS, and Linux, risk-ranked and reported, independently of your RMM.
Lavawall® monitors releases and CVEs for TightVNC through public information and proprietary statistical analysis, and can patch it automatically across your fleet.