Classification: Important, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 8.8, CVEs: CVE-2026-18264, Summary: The following problem has been reported by ZeroDayInitiative (ZDI-26-483). A logged user could exploit the nx user via some server handlers to gain privileges for executing arbitrary operations. This issue affected NoMachine v9 and v8. It is now fixed in v9.8.2