Logo
Decide better.Live better.
Logo
Decide better.Live better.

Telegram hit by critical zero‑day (ZDI‑CAN‑30207). A CVSS 9.8 zero‑day lets attackers hijack any Telegram account; 120 days to patch

Telegram hit by critical zero‑day (ZDI‑CAN‑30207)

A critical zero‑day (ZDI‑CAN‑30207) affecting Telegram messenger was disclosed by 3Side on March 26, 2026. The vulnerability scores a CVSS 9.8 rating, enabling remote, no‑click account takeover. Telegram has been given 120 days to release a fix and has not yet responded. Users should watch for updates and apply extra security measures until the patch arrives.

28 March 2026

News

banner

Telegram messenger faces a critical zero-day vulnerability discovered by security firm 3Side and reported on March 26, 2025, that enables remote compromise without user interaction.

The flaw, logged in the Zero Day Initiative (ZDI) registry as ID ZDI-CAN-30207, received a 9.8 rating from the Common Vulnerability Scoring System (CVSS), placing it in the highest danger category. Researchers say the attack can be launched remotely over the network, requires low exploitation complexity, and does not need the victim to take any action or grant system privileges.

Telegram's development team was notified on March 26 and has 120 days under Zero Day Initiative policy to release a fix before technical details are publicly disclosed. The company has not yet commented on the finding. Users should monitor for updates and consider implementing additional security measures until a patch is deployed.

What is this about?

Feed