Minimum OS: Windows 7

logo

UltraVNC 1.8.2.9


Release summary — Sept 2026
1.8.2.9
winvnc: fixed purple halo around cursors (Busy, Working in Background, hand pointer) by treating magenta-like shadow pixels as transparent
winvnc: -InfoMsg text from the viewer is now displayed correctly as UTF-8 (accept/reject dialog + tray notification), preserving non-ASCII characters
winvnc: fixed VNC_OSVersion use-after-free on reset (crash on server shutdown/restart)
 
1.8.2.8
winvnc: fixed password detection - encrypted passwords starting with a 0x00 byte were treated as empty
winvnc: fixed initial black screen on multi-monitor setups (first update was empty)
winvnc: fixed wrong screen offset in "show all monitors" mode (top used X instead of Y offset)
winvnc: added missing js file for the buildin webserver

1.8.2.6
Add noVNC webviewer + TLS support  ( replacement java viewer) + mslogon II
Security audit hardening: file-transfer path pinning, DLL search hardening, service command hygiene
Complete German translation for UltraVNC Server dialogs #380
Portable: No explorer shell available (for example WinPE). Keep server running headless. (#379)
save viewer password in the credential manager when saved is checked and reuse next time
optimization ( small rects)
synced langauge layouts

1.8.2.5
viewer layout 
FileTransfer: support Legacy viewer recv fix
FileTransfer: multi delete files wasn't correct working 
Changing settings encryption on/off doesn't require a restart anymore
horizontal mouse scrolling #369
add \ as escape to enter a " in the password  vncviewer.exe -password "123\"4567"
clipboard encoding fix
security fixes
custom service: using own servicename.ini should not use ultravnc.ini
layout changes viewer
Expand text boxes, Fix logo positions (#374)

Changes 1.8.2.4
Filetransfer from commandline

Changes 1.8.2.3
Fixed
CVE-2026-7840  |  CVE-2026-7839  |  CVE-2026-7838  |  CVE-2026-7831  |  CVE-2026-7830
CVE-2026-7829  |  CVE-2026-7828  |  CVE-2026-44040  |  CVE-2026-44041  |  CVE-2026-44042
repeater: security fixes 
stronger encryption for mslogon user/passwd 
// MS-Logon III: X25519 + AES-256-GCM, replaces weak 31-bit DH (FINDING-002)
layout fix to make translations fit
automated filetransfer
update translations
added translation (ru)
skip close request when sc_exit is used
REGRESSION: Repeater:proxy setting not loading correctly on VNC Viewer in 1.8.2.2 #359
#360 #361 timeouts and blacklist
---CVE INFO----
CVE-2026-7840    Pre-auth repeater hdrbuf overflow (F-005)    9.8    ✔ FIXED
CVE-2026-7839    Hardcoded repeater admin password (F-006)    9.1    ✔ FIXED
CVE-2026-7838    Viewer reasonLen heap overflow (F-010)    8.8    ✔ FIXED
CVE-2026-7831    Viewer nameLength off-by-one (F-011)    7.5    ✔ FIXED
CVE-2026-7830    MS-Logon II weak DH / broken RNG (F-002)    7.4    ✔ FIXED
CVE-2026-7829    Repeater rule-parser OOB write (F-007)    7.2    ✔ FIXED
CVE-2026-7828    win_log allocation integer overflow (F-009)    5.3    ✔ FIXED
CVE-2026-44040    Weak RNG in vncauth.c (F-001)    4.8    ✔ FIXED
CVE-2026-44041    vncWc2Mb OOB wcslen read (F-004)    4.3    ✔ FIXED
CVE-2026-44042    wi_uudecode boundary off-by-one (F-008)    3.7    ✔ FIXED

Note on CVE-2026-7830 — MS-Logon II / Broken DH

During fix validation we observed that the 31-bit DH implementation in MS-Logon II was documented by the original author in 2006 as a deliberate workaround ("I know that this is no breakthrough in modern cryptography. It's just a patch/kludge/workaround.") rather than an inadvertent weakness. We are updating the CVE-2026-7830 NVD description accordingly:

    The weakness is scoped to the legacy MS-Logon II authentication path (rfbUltraVNC_MsLogonIIAuth), retained solely for backward compatibility with unupgraded servers.
    The preferred path in the fix build is MS-Logon III (rfbUltraVNC_MsLogonIIIAuth) — X25519 ECDH + AES-256-GCM via libsodium — providing 128-bit equivalent security.
    When both client and server support MS-Logon III, MS-Logon II is never negotiated.
    A passive downgrade risk remains for connections to unupgraded servers or under active MITM.
    We recommend users upgrade server components to enable MS-Logon III and disable MS-Logon II in server configuration where possible.

CVSS 7.4 (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N) is unchanged — AC:H reflects the legacy-server or MITM precondition.
----------------

SHA256 hash of UltraVNC_1829_X86_Setup.exe:
f304611fc91cc34510c7aee0fd40e8f086f4c120fe92a42d423795f56a200a94

SHA256 hash of UltraVNC_1829_X64_Setup.exe:
7a0c954c1cc5a8a471629b2a68e2406ac495c9263154983e3af19eab7dc57f61

SHA256 hash of UltraVNC_1829.zip:
ed57cb9f236aad9116b28c9b40f2a918cb6ac6c12ed1669a730a79b1bc0496f7

SHA256 hash of UltraVNC_1829_x86_Setup.msi:
d74c0bd11d6c41ca9f80bc7a61906ffe76dd88f3056f4dce4209ff42981941af

SHA256 hash of UltraVNC_1829_x64_Setup.msi:
403b723ba78d590641b369ba4e4652a5a468192efecf4b355589ab3402688253

 

INSTALLERS

Downloads:
binaryultravnc 1829 X86 setup 1.8.2.9 NEW

UltraVNC 1.8.2.9 X86 setup

File Size 196
Download 12

binaryultravnc 1829 X64 setup 1.8.2.9 NEW

UltraVNC 1829 X86 setup

File Size 196
Download 11

binary ultravnc 1829 msi X64 1.8.2.9 NEW

UlltraVNC 1829 msi X64

File Size 6488064
Download 7

binaryultravnc 1829 msi X86 1.8.2.9 NEW

UltraVNC 1829 msi X86

File Size 196
Download 1

Zipped x86/x64 binaries

zipultravnc 1.8.2.9 zip 1.8.2.9 NEW

UltraVNC 1.8.2.9 zip  32/64

File Size 196
Download 1
 
 

UltraVNC – Changelog

1.8.2.4 – June 2026

  • Filetransfer using commandline

1.8.2.3 – June 2026

  • Fixed
    CVE-2026-7840 | CVE-2026-7839 | CVE-2026-7838 | CVE-2026-7831 | CVE-2026-7830
    CVE-2026-7829 | CVE-2026-7828 | CVE-2026-44040 | CVE-2026-44041 | CVE-2026-44042
  • stronger encryption for mslogon user/passwd // MS-Logon III: X25519 + AES-256-GCM, replaces weak 31-bit DH (FINDING-002)
  • layout fix to make translations fit
  • update translations ( ru added)
  • skip close request when sc_exit is used
  • REGRESSION: Repeater:proxy setting not loading correctly on VNC Viewer in 1.8.2.2 #359
  • #360 #361 timeouts and blacklist

    ---CVE INFO----
    CVE-2026-7840 Pre-auth repeater hdrbuf overflow (F-005) 9.8 ✔ FIXED
    CVE-2026-7839 Hardcoded repeater admin password (F-006) 9.1 ✔ FIXED
    CVE-2026-7838 Viewer reasonLen heap overflow (F-010) 8.8 ✔ FIXED
    CVE-2026-7831 Viewer nameLength off-by-one (F-011) 7.5 ✔ FIXED
    CVE-2026-7830 MS-Logon II weak DH / broken RNG (F-002) 7.4 ✔ FIXED
    CVE-2026-7829 Repeater rule-parser OOB write (F-007) 7.2 ✔ FIXED
    CVE-2026-7828 win_log allocation integer overflow (F-009) 5.3 ✔ FIXED
    CVE-2026-44040 Weak RNG in vncauth.c (F-001) 4.8 ✔ FIXED
    CVE-2026-44041 vncWc2Mb OOB wcslen read (F-004) 4.3 ✔ FIXED
    CVE-2026-44042 wi_uudecode boundary off-by-one (F-008) 3.7 ✔ FIXED

    Note on CVE-2026-7830 — MS-Logon II / Broken DH

    During fix validation we observed that the 31-bit DH implementation in MS-Logon II was documented by the original author in 2006 as a deliberate workaround ("I know that this is no breakthrough in modern cryptography. It's just a patch/kludge/workaround.") rather than an inadvertent weakness. We are updating the CVE-2026-7830 NVD description accordingly:

    The weakness is scoped to the legacy MS-Logon II authentication path (rfbUltraVNC_MsLogonIIAuth), retained solely for backward compatibility with unupgraded servers.
    The preferred path in the fix build is MS-Logon III (rfbUltraVNC_MsLogonIIIAuth) — X25519 ECDH + AES-256-GCM via libsodium — providing 128-bit equivalent security.
    When both client and server support MS-Logon III, MS-Logon II is never negotiated.
    A passive downgrade risk remains for connections to unupgraded servers or under active MITM.
    We recommend users upgrade server components to enable MS-Logon III and disable MS-Logon II in server configuration where possible.

    CVSS 7.4 (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N) is unchanged — AC:H reflects the legacy-server or MITM precondition.
    ----------------



1.8.2.2 – May 2026

  • Translation
  • UI layout fixes

1.8.2.1 – May 2026

  • CVE-2026-3787 CWE-428
  • remove creation empty folder for snapshots on init FT history change font setting

1.8.2.0 – May 2026

  • Bridge removed (not functional, moved to 1.9.x branch)

1.8.1.1 – May 2026

  • FileTransfer fixes
  • Use Windows 7 compatible zip/unzip option
  • Security fix

1.8.1.0 –May 2026

  • FileTransfer fixes

1.8.0.9 – April 2026

  • FileTransfer fixes

1.8.0.8 – April 2026

  • Fix logging: correct initialization order — log file now properly opened on startup (service + app mode)
  • Fix #340: logging not active on server startup
  • Fix #259: Desktop/Downloads show 'media not present' when running as service
  • Fix #189: file transfer fails after window close in kiosk/no-shell mode
  • Fix: prevent International keys and Alternate keyboard from being enabled simultaneously
  • Fix new zip/unzip bug
  • Fix FT: Refresh button misaligned on resize; stale !UVNCDIR- entry after folder receive
  • Fix virtual key (virtKey!=69)
  • File Transfer: update zip/unzip with Unicode + long filename support
  • File Transfer: add progress indication while folder is being zipped
  • File Transfer: add Refresh button
  • File Transfer: show file extension and date columns
  • Update CMake and Qt project files
  • Installer and minor changes

1.8.0.6 – April 2026

  • FileTransfer fix folder transfer
  • OpenSSL 3.6.2
  • libsodium 1.0.22
  • setpasswd/createpasswd write to %ProgramData% instead of current folder
  • Fix path mslogon

1.8.0.5 – April 2026

  • FileTransfer: bigger buffers needed for UTF-8/UTF-16
  • UI Unicode fixes
  • Unicode logging
  • Baseline library updates:
    • libjpeg-turbo 3.1.4.1
    • liblzma 5.8.3
    • libsodium 1.0.21#1
    • zlib 1.3.1
    • zstd 1.5.7
    • OpenSSL 3.6.1#3

1.8.0.4 – April 2026

  • Unicode and encryption plugin
  • Unicode UI

1.8.0.3 – March 2026

  • Sync server and viewer keyboard handling — fixes:
    • Incorrect handling of Cyrillic (0x06a1-0x06ff) — treated as Unicode instead of X11 keysym
    • Incorrect handling of Greek (0x07a1-0x07f9)
    • Incorrect handling of Hebrew (0x0cdf-0x0cfa)
    • Incorrect handling of Arabic (0x05ac-0x05fe)
    • Incorrect handling of Thai (0x0da1-0x0df9)
    • Incorrect handling of Korean (0x0ea1-0x0eff)
    • Unicode keysyms (0x01000000+) not handled

1.8.0.2 – March 2026

  • Unicode viewer fixes

1.8.0.0 – March 2026

  • FileTransfer, Chat, keyboard Unicode support
  • Minor optimizations
  • VNCViewer Unicode build

1.7.1.10 – February 2026

  • FileTransfer Unicode
  • Fix FileTransfer failure on RDP sessions
  • Use system fonts for chat

1.7.1.9 – February 2026

  • FileTransfer Unicode
  • Mark inaccessible folders red in FileTransfer
  • Use secure copy_s functions
  • LoadLibrary: limit path search

1.7.1.7 – February 2026

  • Copy/paste removed
  • Extended FileTransfer dialog

1.7.1.6 – February 2026

  • Longer host field
  • Two-way copy/paste
  • Mark inaccessible folders red in FileTransfer
  • Fix save/load config file
  • Accept/Refuse: default changed to query

1.7.1.5 – February 2026

  • Speed up FileTransfer
  • Fix color cursors
  • Fix FileTransfer and unreadable folders
  • Fix viewer load/save settings, encryption saving, buffer overrun
  • Viewer: larger host field

1.7.1.1 – January 2026

  • UniChat (Unicode chat)
  • Copy/paste files
  • Listen mode fix

1.7.1.0 – December 2025

  • FileTransfer optimized (minimum 2x faster)
  • Bridge mode
  • Translations (French, German, Spanish, Chinese)
  • Use proper INI path (ultravnc.ini) + portable mode
  • Fix: Accessibility enlarged cursor showed a black rectangle
  • Fix IPv6
  • Fix 'Use Only Default ConfigFile' option
  • Fix quick options
  • Update libraries:
    • libjpeg-turbo: 3.1.2
    • liblzma: 5.8.1
    • OpenSSL: 3.6.0#3
    • zlib: 1.3.1
    • zstd: 1.5.7

1.6.4.0 – June 2025

  • Update viewer layout
  • Viewer, SessionDialog wrong size after dpi change #278
  • Fix to small msg buffer size
  • Fix big border (ThomasLevering)
  • Update GNOME /QEMU display settings text + zlibbuffer was unneeded recrated
  • Fix vncviewer crash #58
  • FIX empty password detection, also for SC
  • Fix bug in undefer_input() that misplaced the input state. (#272)
  • Do not accept Anonymous TLS sub-types during VeNCrypt authentication (#274)
    But allow fallback to standard RFB types (e.g. rfbVncAuth)

1.6.1.0 – May 2025

  • Fixed Chat Japanese chars
  • Fixed saving listenport
  • Fixed saving custom messages accept/reject
  • Fixed save settings should not reload defaults

1.6.0.0 – April 2025

  • Updated dev version to release.


1.5.0.18-dev – April 2025

  • Use single DLL instead of V2 version.


1.5.0.17-dev – April 2025

  • International keyboard fix.


1.5.0.16-dev – April 2025

  • Viewer defaults were not loading.

  • Possible keyboard fix (to verify) — supports characters like +ěščřžýáíé=´.

  • Renamed authSSPV2 loggingV2.dll to fix Event Viewer messages on x64.

  • Echoserver fix.

  • Fix for broken sc_20 build.

Keyboard Notes:

  • The "international keyboard" option must be enabled on the server.

  • Only tested using a virtual Czech keyboard.

Bug Detail:

  • Viewer defaults missing caused issues like incorrect INI viewonly mode and wrong encoding settings.


1.5.0.15-dev – March 2025

  • File Transfer: Fixed buffer overflow and memory leak (#254).

  • Added service to settings.

  • Log file movement fix.


1.5.0.14-dev – March 2025

  • Slider fix.

  • Fixed DSMPlugin and MS-Logon settings when running as standalone.

  • Resolved bug where own messages weren’t logged due to logfile move.


1.5.0.13-dev – March 2025

  • Moved log file to the ultravnc.ini folder.


1.5.0.12-dev – March 2025

  • File Transfer window size fix.

  • Fix for crash on Microsoft Windows 7.

  • Installer: Added "Run as admin" to settings shortcut.

  • Installer: .ini file now copied to ProgramData before service starts.


1.5.0.10-dev – March 2025

  • DSMPlugin configuration fix.

  • Fixed "Apply Save Settings" functionality.

  • Clearing admin password also clears VNC password.

  • ISOtime added in About window + smaller max size.


1.5.0.9-dev – March 2025

  • Removed installer popups.

  • Fixed issue where some settings weren’t saved correctly.


1.5.0.8-dev – March 2025

  • Save settings fix.

  • Typo correction.

  • Added Bluesky integration.


1.5.0.7-dev – March 2025

  • Command line can now overwrite default values.

  • Settings dialog can run standalone.

  • Viewer: Focus set to host input field.

  • General bug fixes.


1.5.0.5-dev – February 2025

  • Fallback to old folder if ultravnc.ini is missing.

  • Command line options take priority in Viewer.

  • Encryption fix for viewonly (VNC password).

  • UI/UX: Settings dialog enable/disable cosmetic fix.

  • Plugin architecture check (32/64-bit) before use.

  • Chunked messages and default client certs allowed in TLS (#250).

  • Rules fix.


1.5.0.4-dev – February 2024

  • UI update.

  • Moved ini file to ProgramData.

  • Bug fixes (see Git).

  • Added admin password functionality.


1.5.0.3-dev

  • UI corrections.


1.5.0.2-dev

  • Merged IPv4 & IPv6 into a single EXE with switchable property.

  • Fixed RealVNC UDP port usage.

  • UI improvements: layout and icons.


1.5.0.1-dev

  • Reverted fonts in File Transfer.

  • Fullscreen: Added Chat and File Transfer to topbar.


1.5.0.0-dev

  • DirectX reconnect fix.

  • Added extra links.

  • Text/version info fixes.

  • Switched to vcpkg for easier library maintenance.

  • Fixed stack corruption (#185).


1.4.4.0-dev

  • Code cleanup.

  • UI spellcheck and standardization.

  • TLS: Added CertVerifyCertificateChainPolicy API (#144).

  • Switched to Arial font.

  • TLS-encrypted transport via VeNCrypt authentication (#142).

  • WIP: RSA-AES auth & encryption (#139).

  • Fixed typo: "Repetear" → "Repeater" (#138).

  • Windows Recovery Environment (WinRE 10) fix.

  • Snapshot naming now sortable by date.

  • Unified omnithread usage for Server and Viewer.

  • Reinit D3D device on invalid pre-update (#130).

  • SC: UAC restoration with try/catch.

  • Scrollbar added to properties.

  • Fixed group default settings load order.

  • SC UAC reset fix.

  • Able to connect to Debian v12 "bookworm" via WayVNC (#133).

  

License

GNU GENERAL PUBLIC LICENSE (GPL)

This program is free software: you can redistribute it and/or modify
it under the terms of the GNU General Public License as published by
the Free Software Foundation, either version 3 of the License, or
(at your option) any later version.

This program is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
GNU General Public License for more details.

https://www.gnu.org/licenses