TeamViewer urges users to patch five severe flaws now

TeamViewer urges users to patch five severe flaws now

TeamViewer is asking customers to update their remote access software "as soon as possible" after fixing five high-severity vulnerabilities in its client and host products. The company published the advisory on Tuesday. It is unusual for TeamViewer to push users this directly to secure their systems.

The flaws affect TeamViewer Full Client and Host, along with related services. The fixes ship in TeamViewer version 15.82 and in supported maintenance and legacy releases.

Access control bypass tops the list

The most serious issue is CVE-2026-92370, a remote session access control bypass. It comes from an improper access control weakness in TeamViewer Full Client and Host on Windows, Linux and macOS.

According to TeamViewer, remote threat actors could exploit it to carry out unauthorized actions that lead to remote code execution on targeted systems.

The other four vulnerabilities are:

  • a path traversal flaw (CVE-2026-19743)
  • a heap-based buffer overflow (CVE-2026-92368)
  • a time-of-check time-of-use (TOCTOU) race condition (CVE-2026-92369)
  • an improper path validation issue (CVE-2026-92371)

Attackers who abuse these bugs could run code with the privileges of the current user. They could also escalate privileges to NT AUTHORITY/SYSTEM on Windows or root on other platforms.

"TeamViewer strongly recommends that all users update to the latest available version as soon as possible," the company said.

"TeamViewer has released security updates addressing multiple vulnerabilities affecting TeamViewer Full Client and Host and related services," it added.

No known exploitation yet

TeamViewer says it has not found publicly available exploit code or signs that the flaws are being used in attacks.

"These vulnerabilities have been resolved in TeamViewer Clients version 15.82 as well as supported maintenance and legacy releases," the company noted. "TeamViewer is not aware of any public disclosure or active exploitation in the wild."

Even so, the vendor recommends that all customers move to 15.82 or a fixed maintenance or legacy build.

A popular tool, and a popular target

TeamViewer's remote access and desktop sharing software is widely used because it is simple and capable. The same qualities appeal to cybercriminals. Ransomware gangs and other threat actors regularly abuse it to reach victims' machines remotely and to deploy malware and other malicious tools.

The company has also dealt with intrusions into its own network over the past decade. The first breach took place in 2016 and was disclosed in May 2019. It was linked to Chinese threat actors who used the Winnti backdoor.

The second incident hit TeamViewer's internal corporate network and was disclosed two years ago. Days after the announcement, it was attributed to Midnight Blizzard, a Russian state-backed hacking group also tracked as APT29, Nobelium and Cozy Bear.

Our Take

Admins should not let the lack of known exploitation lower the priority of this update. TeamViewer is installed on a huge number of endpoints and gives direct remote control of those machines. A bug chain that leads to remote code execution or SYSTEM-level access is exactly what attackers look for. Now that the fixes are public, attackers can compare patched and unpatched builds to work out how the bugs function. That usually shortens the time before exploit code appears.

The pattern is familiar. Remote access and edge products have been hit hard recently, with the Citrix NetScaler flaw CVE-2026-88771 moving into mass exploitation. Ransomware operators are also quick to adopt fresh bugs, as the TeamCity flaw now used by ransomware gangs showed. Criminals already abuse TeamViewer in its normal, unpatched-or-not form, so a weakness that bypasses its access controls would be an obvious upgrade for them.

Organizations should check which TeamViewer versions are running across their fleet, including forgotten installs on servers and older machines. It is also worth asking whether the tool needs to be installed everywhere it is today. Over the coming weeks, watch for proof-of-concept code, technical write-ups from researchers, and any change in TeamViewer's position on in-the-wild exploitation.