CERT/CC disclosed three critical zero-day vulnerabilities in ViewSonic vCast software for Android-based ViewBoard interactive displays: CVE-2026-82987, CVE-2026-82988, and CVE-2026-82989. An attacker on the same network can exploit exposed unauthenticated services to capture the display screen, inject input commands, and remotely install an attacker-controlled Android APK without user interaction.
Chaining the flaws can enable surveillance of displayed content, arbitrary code execution, persistence, and effective full control of affected boards. A compromised ViewBoard could also serve as a foothold for lateral movement into connected education or enterprise networks. CERT/CC said it had been unable to reach ViewSonic and no fixes had been provided at disclosure; organizations should isolate affected displays, tightly restrict network access, and monitor them until patches are available.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
CERT/CC published Vulnerability Note VU#234131 covering CVE-2026-82987, CVE-2026-82988, and CVE-2026-82989 in ViewSonic vCast software for Android-based ViewBoard displays. The unauthenticated flaws enable input injection, screen capture, and installation of an attacker-supplied APK; they can be chained by a same-network attacker to potentially gain full device control and establish a foothold for lateral movement.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcescworld.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.