TeamViewer has warned its users of five high-severity security vulnerabilities , urging them to install the available updates immediately. The issues affect the company's remote access software , including the TeamViewer Full Client and Host applications , and could, under certain conditions, allow unauthorized actions to be performed or elevated privileges to be gained on target systems.

The company has released patches in version 15.82, which addresses all five vulnerabilities. While it has not reported any evidence of active exploitation or publicly available attack code, it recommends that its customers upgrade their software without delay.
The most serious vulnerability leads to remote code execution
The most significant of the security issues is listed as CVE-2026-92370 and concerns the bypass of access control mechanisms in remote sessions. The vulnerability is found in TeamViewer Full Client and Host for Windows, Linux and macOS.
Access control mechanisms are a key element of the security of a remote administration tool, as they determine who can connect to a computer and what actions they are allowed to perform. If these controls are bypassed, an attacker may gain capabilities that would normally require authorization.
See also: NetScaler vulnerability exploited to deploy WHIPSHOT & SLAPSHOT
According to TeamViewer's description, this vulnerability could allow remote attackers to perform unauthorized actions, potentially resulting in remote code execution on affected systems. The actual exploitability depends on the specific environmental conditions and software configuration.
Remote code execution is considered a particularly serious risk, as it can be a starting point for further actions, such as installing malware, accessing files, or attempting to expand the attacker's presence on the corporate network.

The remaining four vulnerabilities and potential risks
The remaining vulnerabilities fixed cover different categories of software bugs, which could be exploited for code execution or privilege escalation.
Specifically, CVE-2026-19743 concerns a path traversal. Such errors occur when an application does not properly check the file paths it receives or processes, resulting in the possibility of accessing files or directories outside of the permitted limits.
CVE -2026-92368 is related to a buffer overflow in heap memory. Depending on the exploitation conditions, such memory management issues can cause application instability or create conditions for malicious code execution.
Meanwhile, CVE-2026-92369 concerns a time-of-check time-of-use (TOCTOU) race condition. This type of error occurs when the state of a resource changes between the time an application checks it and the time it uses it. If an attacker can exploit this time gap, they can bypass certain security checks
Finally, CVE-2026-92371 is related to incorrect path validation. As with path traversal, insufficient path validation can allow unwanted file access or contribute to other attacks.
See also: OpenSSL: Critical DTLS vulnerability leaks heap memory
According to the announcement, these vulnerabilities could allow local attackers to execute code with the rights of the logged-in user or gain elevated privileges, even reaching the NT AUTHORITY/SYSTEM level on Windows or root on Linux and macOS systems. Access to such privilege levels could give the attacker broader control over the system.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Version 15.82 includes the necessary fixes
TeamViewer confirmed that the five vulnerabilities have been addressed in version 15.82, as well as in supported maintenance releases and older versions of the software where the corresponding fixes are provided.
The company urged its customers to install the latest appropriate version as soon as possible. System administrators should check which computers are running the Full Client and Host applications, confirm the installed versions, and schedule the upgrade on all affected systems.
Particular attention is needed in corporate environments where TeamViewer is installed on multiple workstations or servers, as well as on computers used for remote technical support. An update on a single computer is not enough if other installations are still using vulnerable versions.
TeamViewer said it is not aware of any public disclosure or active exploitation of these vulnerabilities. However, this is not a reason to postpone the update, as the absence of known attacks does not guarantee that the issues will not be exploited in the future.
See also: Kiteworks: Critical Vulnerability Fix – Outage Lifted

TeamViewer's security incident history
TeamViewer has faced cybersecurity incidents in the past. A breach linked to its corporate network in 2016 was publicly disclosed in May 2019 and was associated with the use of the Winnti, which has been linked in public reports to Chinese threat actors.
Additionally, in 2024, the company announced a new incident involving its internal corporate environment. The incident was later linked to the Russian cyberespionage Midnight Blizzard, also known as APT29, Nobelium, and Cozy Bear.
The previous incidents do not prove that the new vulnerabilities are related to these attacks. However, they highlight the importance of continuously monitoring threats and timely applying patches to software that provides access to critical systems.
source: www.bleepingcomputer.com
