DKDKCISSPSearch
Vulnerabilities

TeamViewer urges users to patch severe flaws “as soon as possible

Remote access software company TeamViewer warned customers on Tuesday to immediately patch a set of high-severity vulnerabilities affecting its client and host software.

DKCISSP News DeskBleepingComputer30 Sept 2026, 5:55 pm
TeamViewer urges users to patch severe flaws “as soon as possible
Image courtesy of BleepingComputer. Original report
DKCISSP REPORT

Remote access software company TeamViewer warned customers on Tuesday to immediately patch a set of high-severity vulnerabilities affecting its client and host software.

The highest-severity flaw is a remote session access control bypass ( CVE-2026-92370 ) stemming from an improper access control weakness in TeamViewer Full Client and Host software for Windows, Linux, and macOS that could let remote threat actors perform unauthorized actions leading to remote code execution on targeted systems.

The other four security issues addressed on Tuesday are a path traversal ( CVE-2026-19743 ), a heap-based buffer overflow ( CVE-2026-92368 ), a time-of-check time-of-use (TOCTOU) race condition ( CVE-2026-92369 ), and an improper path validation ( CVE-2026-92371 ) that will allow local attackers to gain code execution remotely with the privileges of the current user or escalate privileges to NT AUHORITY/SYSTEM or root.

the company warned in a rare advisory urging customers to secure their systems.

Although it has not found evidence that the vulnerabilities have publicly available exploit code or are being actively exploited, the company urged customers to update to TeamViewer version 15.82, which addresses these security flaws.

Over the last decade, TeamViewer has also disclosed several breaches of its corporate network, the first in 2016 linked to Chinese threat actors who used the Winnti backdoor malware and disclosed in May 2019.

While TeamViewer's remote access and desktop sharing software is valued for its simplicity and capabilities, cybercriminals (including ransomware gangs) also often abuse it to access victims' systems remotely and to deploy malware and malicious tools.

The second incident affected the company's internal corporate network and was disclosed two years ago .

Days later, the breach was linked to a Russian state-backed hacking group tracked as Midnight Blizzard (also known as APT29, Nobelium, Cozy Bear).

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

What happened

Remote access software company TeamViewer warned customers on Tuesday to immediately patch a set of high-severity vulnerabilities affecting its client and host software.

The highest-severity flaw is a remote session access control bypass ( CVE-2026-92370 ) stemming from an improper access control weakness in TeamViewer Full Client and Host software for Windows, Linux, and macOS that could let remote threat actors perform unauthorized actions leading to remote code execution on targeted systems.

The other four security issues addressed on Tuesday are a path traversal ( CVE-2026-19743 ), a heap-based buffer overflow ( CVE-2026-92368 ), a time-of-check time-of-use (TOCTOU) race condition ( CVE-2026-92369 ), and an improper path validation ( CVE-2026-92371 ) that will allow local attackers to gain code execution remotely with the privileges of the current user or escalate privileges to NT AUHORITY/SYSTEM or root.

What changed

the company warned in a rare advisory urging customers to secure their systems.

Although it has not found evidence that the vulnerabilities have publicly available exploit code or are being actively exploited, the company urged customers to update to TeamViewer version 15.82, which addresses these security flaws.

Over the last decade, TeamViewer has also disclosed several breaches of its corporate network, the first in 2016 linked to Chinese threat actors who used the Winnti backdoor malware and disclosed in May 2019.

Who is affected

While TeamViewer's remote access and desktop sharing software is valued for its simplicity and capabilities, cybercriminals (including ransomware gangs) also often abuse it to access victims' systems remotely and to deploy malware and malicious tools.

The second incident affected the company's internal corporate network and was disclosed two years ago .

Why it matters

Days later, the breach was linked to a Russian state-backed hacking group tracked as Midnight Blizzard (also known as APT29, Nobelium, Cozy Bear).

Response

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Attribution

BleepingComputer: Remote access software company TeamViewer warned customers on Tuesday to immediately patch a set of high-severity vulnerabilities affecting its client and host software.

What to watch next

Watch for additional victim details, indicators of compromise and follow-on exploitation reports.

Watch for revised vendor guidance, fixed versions and mitigation updates.

MORE IN VULNERABILITIES

More cybersecurity reporting

Critical FortiMail zero-day exploited in the wild (CVE-2026-104286) - Help Net SecurityHelp Net Security · 2 Oct 2026, 2:20 pmCritical FortiMail zero-day exploited in the wild (CVE-2026-104286) - Help Net SecurityHelp Net Security · 2 Oct 2026, 2:20 pmTwo Zero-Days Exploited in Attack on Dutch Institute for VulnerabilityInfosecurity Magazine · 2 Oct 2026, 1:55 pmTwo Zero-Days Exploited in Attack on Dutch Institute for VulnerabilityInfosecurity Magazine · 2 Oct 2026, 1:55 pm