References https://www.sentinelone.com/vulnerability-database/cve-2026-7701/ https://infosecwriteups.com/typo-trouble-exploring-the-telegram-python-rce-vulnerability-b7bc8a12c9ba https://medium.com/@0xrave/how-a-simple-typo-in-telegrams-code-unleashed-remote-code-execution-fdc5156994e6 https://x.com/DarkWebInformer/status/1951302045585002626 https://beyondmachines.net/event_details/possible-rce-flaw-in-telegram-desktop-app-disable-auto-download-z-m-u-c-h https://www.wublock123.com/index.php?m=content&c=index&a=show&catid=46&id=25774 https://www.binance.com/lo-LA/square/post/6536115626738 https://news.ycombinator.com/item?id=39978377 https://positive.security/blog/url-open-rce https://blog.cschad.com/cti/telegram-desktop-zero-day-24-04-11/ https://cryptorank.io/news/feed/d3166-telegram-debunks-reported-vulnerability-in-desktop-app-confirms-mobile-security https://www.ctfiot.com/173475.html https://www.zero-day.cz/database/485/ https://www.exploit-db.com/exploits/50247 https://nvd.nist.gov/vuln/detail/CVE-2021-47793 https://www.bannedbook.org/bnews/itnews/20240410/2022974.html https://www.secrss.com/articles/68394 https://feedly.com/cve/vendors/telegram https://app.opencve.io/cve/?product=telegram_desktop&vendor=telegram https://www.bleepingcomputer.com/news/security/telegram-fixes-windows-app-zero-day-used-to-launch-python-scripts/ https://www.redhotcyber.com/en/post/just-one-telegram-sticker-can-hack-you-the-critical-9-8-rce-vulnerability-still-has-no-patch/ https://cybernews.com/security/telegram-zero-click-vulnerability-animated-stickers/ https://www.scworld.com/brief/new-critical-telegram-zero-click-issue-threatens-total-device-compromise https://github.com/gameworkerkim/Telegram-0-Click-RCE-SECURITY-VULNERABILITY-ANALYSIS-REPORT/blob/main/Telegram%200-Click%20RCE_ENG.md https://nvd.nist.gov/vuln/detail/CVE-2021-47793 https://securelist.com/zero-day-vulnerability-in-telegram/83800/ https://www.linkedin.com/posts/misaylor_telegram-messenger-vulnerability-risks-activity-7184245028016332800-hUxW https://www.binance.com/en/square/post/6739211355322 https://thecyberexpress.com/telegram-vulnerability-refutes-certik-alert/ https://cryptoslate.com/telegram-debunks-reported-vulnerability-in-desktop-app-confirms-mobile-security/ https://discuss.techlore.tech/t/potential-vulnerability-in-telegram-desktop-rce-through-media-files/8064
Related Vulnerabilities旭辰資訊|SmartIT Desktop Manager - 存在4個漏洞Docker Desktop Engine API 未授权访问漏洞新华通软件云平台 /Main/Desktop/Default.aspx 权限绕过漏洞PoCCVE-2018-13980: Zeta Producer Desktop CMS <14.2.1 - Local File InclusionPoCCVE-2018-19439: Oracle Secure Global Desktop Administration Console 4.4 - Cross-Site ScriptingPoCCVE-2020-10189: ManageEngine Desktop Central Java DeserializationPoCCVE-2021-44515: Zoho ManageEngine Desktop Central - Remote Code ExecutionPoCCVE-2023-2479: Appium Desktop Server - Remote Code ExecutionPoChongfan-iodesktopdata-sqli: 红帆iOffice ioDesktopData.asmx接口SQL注入PoCjianwen-desktop-ashx-sqli: 建文工程管理系统desktop.ashx存在SQL注入漏洞PoCrdp-connections-without-password-allowed: Remote Desktop Connections Allowed Without PasswordPoCrdp-drive-redirection-allowed: Remote Desktop Users Can Redirect Drives