NoMachine fixed two local vulnerabilities in version 9.4.14 that could let an attacker with low-privileged code execution escalate impact on affected systems. One issue, tracked as CVE-2026-5053 and ZDI-26-247, stems from improper validation of a user-supplied path in environment variable handling and can be abused to delete arbitrary files with root privileges. The flaw was assigned a CVSS 7.1 score.
A second flaw, CVE-2026-5055 / ZDI-26-249, affects the NoMachine Device Server and arises from loading a library from an unsecured location, creating an uncontrolled search path element vulnerability. Successful exploitation could allow arbitrary code execution with SYSTEM privileges, and the issue received a CVSS 7.8 score. Trend Micro's Zero Day Initiative disclosed both advisories publicly after coordinated reporting to the vendor, and credited khongtrang with discovering the privilege-escalation bug.

Get the actors, campaigns, and ATT&CK mapping behind it.
5 events from the most recent confirmed update back to the earliest known activity.
Trend Micro's Zero Day Initiative published coordinated advisories for CVE-2026-5053 (ZDI-26-247) and CVE-2026-5055 (ZDI-26-249). The disclosures described local attacks that could delete arbitrary files as root or execute code with SYSTEM privileges after low-privileged code execution.
NoMachine addressed both disclosed vulnerabilities in version 9.4.14, including the arbitrary file deletion issue and the Device Server uncontrolled search path flaw. The references identify this version as the fix for both CVE-2026-5053 and CVE-2026-5055.
NoMachine published a knowledge base notice stating that version 9.4.14 was available for download. This vendor release predates later public vulnerability disclosures and corresponds to the version that fixed the reported local privilege escalation flaws.
A separate NoMachine vulnerability, later tracked as CVE-2026-5053 and ZDI-26-247, was reported to the vendor. The issue stemmed from improper validation of a user-supplied path in environment variable handling, enabling arbitrary file deletion with root privileges.
A local privilege escalation vulnerability in the NoMachine Device Server, later tracked as CVE-2026-5055 and ZDI-26-249, was reported to NoMachine. The flaw involved loading a library from an unsecured location, allowing low-privileged users to gain SYSTEM privileges.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
kb.nomachine.com
Open sourcezerodayinitiative.com
Open sourcezerodayinitiative.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.