TeamViewer has pushed out an emergency round of security updates after uncovering five vulnerabilities in its Full Client and Host software — including one severe enough that the company is urging every customer to patch immediately.
What happened
The most serious issue, tracked as CVE-2026-92370, is an access control bypass in the remote session handling of TeamViewer's Full Client and Host software on Windows, Linux and macOS. An attacker who can reach an active remote session could exploit the weakness to perform unauthorized actions, up to and including remote code execution on the target machine.
Four additional flaws were patched in the same release:
- A path traversal bug (CVE-2026-19743)
- A heap-based buffer overflow (CVE-2026-92368)
- A time-of-check/time-of-use (TOCTOU) race condition (CVE-2026-92369)
- An improper path validation flaw (CVE-2026-92371) that lets a local attacker escalate privileges to NT AUTHORITY/SYSTEM on Windows or root on Linux/macOS
TeamViewer says it has found no evidence that any of the five bugs have public exploit code or have been exploited in the wild. All are fixed in TeamViewer version 15.82.
Why it matters
TeamViewer sits on millions of endpoints precisely because it's simple to install and grants deep remote control — which is exactly why ransomware crews and other cybercriminals have repeatedly abused it as a foothold to reach victim systems and push malware once inside. A chain from the access-control bypass to code execution would hand an attacker that same level of control without ever needing a phished credential. The company's own history of corporate network breaches — including intrusions attributed to Chinese state-linked actors and, more recently, to the Russian group tracked as Midnight Blizzard (APT29/Cozy Bear) — underscores how attractive TeamViewer's infrastructure and software remain as a target.
What to do
- Update every TeamViewer Full Client and Host install — Windows, Linux and macOS — to version 15.82 or later without delay.
- Treat any environment where TeamViewer is exposed to untrusted networks as higher risk until patched, and review remote-session logs for unusual activity.
- Where possible, restrict who can install or run TeamViewer, enforce MFA on TeamViewer accounts, and keep the client on auto-update going forward.
