Three Zero-Day Vulnerabilities Found in ViewSonic Software
The flaws allow remote attackers on a local network to control ViewBoard displays and install malicious applications.
Updated on Sept. 25, 2026 in Cybersecurity

Live Poll
Do you trust the security of internet-connected smart displays used in your local schools or workplaces?
Researchers have identified three zero-day vulnerabilities in ViewSonic vCast software, which is widely utilized in educational and enterprise ViewBoard displays. CERT/CC officially disclosed these security flaws on September 24, 2026, and no patches are currently available.
Why it matters
These vulnerabilities represent a critical security risk for institutions relying on networked displays, as they permit unauthenticated remote control. The reliance on local network access for exploitation highlights the need for strict network segmentation in environments where these devices are deployed.
The three flaws include CVE-2026-82989, which permits unauthorized screen viewing via API endpoints, and CVE-2026-82988, which allows arbitrary Android application installation through malicious URLs. Additionally, CVE-2026-82987 enables unauthenticated users to execute remote input commands on the host hardware.
The players
ViewSonic
A multinational electronics company specializing in visual display technology including interactive flat-panel ViewBoards.
CERT/CC
The Computer Emergency Response Team Coordination Center, a federally funded research center focused on internet security and vulnerability disclosure.
The details
The vulnerabilities function by leveraging insecure software interfaces within the vCast environment. Attackers exploit CVE-2026-82989 by accessing exposed API endpoints—interface points that allow different software components to communicate—to view display contents, while CVE-2026-82988 allows remote execution of arbitrary code by passing a malicious URL to the device's installer. Access requires that an attacker already possesses a connection to the local network where the ViewBoard is hosted.
Timeline
September 24, 2026: CERT/CC disclosed the vulnerabilities to the public.
The Tech Race
This vulnerability discovery follows a pattern set by the 2021 Kaseya VSA ransomware attack where remote management software became a primary vector for broad-scale institutional compromise. Security researchers are increasingly scrutinizing the proprietary software stacks of IoT and enterprise display vendors to identify similar latent risks before they are weaponized.
Administrators managing ViewBoard displays should isolate affected devices from the open network to prevent unauthorized access until a software update is released. Because no patch currently exists, restricting local network access is the only effective defense against these exploits.
The takeaway
These unpatched vulnerabilities underscore the significant risk posed by proprietary management software in enterprise and classroom environments. Users should monitor official manufacturer support channels for the release of mandatory security updates to remediate these flaws.
Further reading
For more information on identifying and mitigating network threats, visit Cybersecurity.
Live Poll
Do you trust the security of internet-connected smart displays used in your local schools or workplaces?






