CVE-2026-82989
Viewsonic vCast
Published 6 Oct 2026 · updated 6 Oct 2026 · Deferred
9.8 Critical · CVSS 3.1, CISA ADP
Description
There is an input injection in vCast exposed network services in ViewSonic ViewBoard that allows a remote, unauthenticated attacker to inject arbitrary input into service endpoints via network-based HTTP requests to unauthenticated endpoints