ZoomEye finds 5.1 million hosts exposing VNC port 5900
A ZoomEye scan found 5,102,346 addresses with port 5900 open, the default first display port for VNC. Weak authentication schemes and unencrypted deployments leave many of these hosts exposed to credential and session interception.
- Query port="5900" returned 5,102,346 matches collected on 2026-09-23
- Legacy VNC uses a short challenge-response key vulnerable to offline attack
- VNC is often deployed without encryption, exposing credentials and sessions
- Recommendations include tunneling over SSH or VPN and disabling legacy security types
Read next
Security