BleepingComputer 🔐 Cybersecurity 👁 0 📖 2 min read

TeamViewer urges users to patch severe flaws “as soon as possible”

Remote access software company TeamViewer warned customers on Tuesday to immediately patch a set of high-severity vulnerabilities affecting its client and host software. [...]

TeamViewer urges users to patch severe flaws “as soon as possible”

  • September 30, 2026
  • 08:25 AM

TeamViewer

Remote access software company TeamViewer warned customers on Tuesday to immediately patch a set of high-severity vulnerabilities affecting its client and host software.

The highest-severity flaw is a remote session access control bypass (CVE-2026-92370) stemming from an improper access control weakness in TeamViewer Full Client and Host software for Windows, Linux, and macOS that could let remote threat actors perform unauthorized actions leading to remote code execution on targeted systems.

The other four security issues addressed on Tuesday are a path traversal (CVE-2026-19743), a heap-based buffer overflow (CVE-2026-92368), a time-of-check time-of-use (TOCTOU) race condition (CVE-2026-92369), and an improper path validation (CVE-2026-92371) that will allow local attackers to gain code execution remotely with the privileges of the current user or escalate privileges to NT AUHORITY/SYSTEM or root.

"TeamViewer strongly recommends that all users update to the latest available version as soon as possible," the company warned in a rare advisory urging customers to secure their systems.

"TeamViewer has released security updates addressing multiple vulnerabilities affecting TeamViewer Full Client and Host and related services."

Although it has not found evidence that the vulnerabilities have publicly available exploit code or are being actively exploited, the company urged customers to update to TeamViewer version 15.82, which addresses these security flaws.

"These vulnerabilities have been resolved in TeamViewer Clients version 15.82 as well as supported maintenance and legacy releases," it added. "TeamViewer is not aware of any public disclosure or active exploitation in the wild."

While TeamViewer's remote access and desktop sharing software is valued for its simplicity and capabilities, cybercriminals (including ransomware gangs) also often abuse it to access victims' systems remotely and to deploy malware and malicious tools.

Over the last decade, TeamViewer has also disclosed several breaches of its corporate network, the first in 2016 linked to Chinese threat actors who used the Winnti backdoor malware and disclosed in May 2019.

The second incident affected the company's internal corporate network and was disclosed two years ago. Days later, the breach was linked to a Russian state-backed hacking group tracked as Midnight Blizzard (also known as APT29, Nobelium, Cozy Bear).

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat
📰 Read the original article on BleepingComputer

Originally published by BleepingComputer. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.