Skip to main content
CybersecurityVulnerability Management

TeamViewer Warns Users to Patch Flaws Amid Remote Code Execution Risk

Laptop and remote control on a table in a bright, empty office space.

"TeamViewer strongly recommends that all users update to the latest available version as soon as possible," the company warned, in an unusually urgent security advisory issued on Tuesday.

CVE-2026-92370: the single highest-severity flaw

TeamViewer identified a set of high-severity flaws in its Full Client and Host software. The most serious, CVE-2026-92370, is described as a remote session access control bypass caused by an improper access control weakness in TeamViewer Full Client and Host for Windows, Linux, and macOS. According to the company, exploitation of that weakness could let remote threat actors perform unauthorized actions that lead to remote code execution on targeted systems.

The other four vulnerabilities and their effects

Alongside CVE-2026-92370, TeamViewer named four additional vulnerabilities:

  • a path traversal issue, CVE-2026-19743;
  • a heap-based buffer overflow, CVE-2026-92368;
  • a time-of-check time-of-use (TOCTOU) race condition, CVE-2026-92369; and
  • an improper path validation, CVE-2026-92371.

The advisory states those flaws "will allow local attackers to gain code execution remotely with the privileges of the current user or escalate privileges to NT AUHORITY/SYSTEM or root." Those descriptions indicate a range of impacts from remote code execution to local privilege escalation depending on the specific flaw and context.

Patched versions: TeamViewer Clients version 15.82 and supported maintenance and legacy releases

TeamViewer said it has released updates that address the issues in TeamViewer Clients version 15.82 as well as in supported maintenance and legacy releases. The company reiterated the immediate recommendation that users update to TeamViewer version 15.82, and it emphasized the urgency by saying users should update "as soon as possible."

TeamViewer also stated it has not found evidence that exploit code for these vulnerabilities is publicly available and that it is "not aware of any public disclosure or active exploitation in the wild." That cautionary note accompanied the company’s push for broad, immediate patching.

How attackers have used TeamViewer and the company's prior incidents

The advisory placed the new flaws in a broader context by noting that cybercriminals — including ransomware gangs — "often abuse" TeamViewer to access victims' systems remotely and to deploy malware and malicious tools. The company also recounted past intrusions into its corporate network: a 2016 breach linked to Chinese threat actors who used the Winnti backdoor and disclosed in May 2019, and a second incident disclosed two years ago that was tied days later to a Russian state-backed group tracked as Midnight Blizzard (also known as APT29, Nobelium, Cozy Bear).

What this means for security teams, end users, and cybercriminals

  • Security teams and IT administrators: Patch management needs to prioritize TeamViewer installations on Windows, Linux, and macOS — updating clients and hosts to version 15.82 or to supported patched maintenance/legacy releases as TeamViewer recommends.
  • End users and general-purpose device owners: Any machine running TeamViewer Full Client or Host should be updated promptly because the disclosed flaws include avenues for remote code execution and for privilege escalation to NT AUHORITY/SYSTEM or root.
  • Cybercriminals and ransomware operators: TeamViewer’s advisory serves as both a reminder and a warning — the vendor reports no known active exploitation or public exploits yet, but the cataloged flaws describe capabilities adversaries typically seek: remote access bypasses, code execution, and privilege escalation.

TeamViewer’s warning is direct and time-bound: it has published fixes (version 15.82 and corresponding maintenance and legacy updates) and says customers should apply them without delay. At the same time, the company reports no evidence the flaws are already being exploited or have been publicly disclosed — a narrow window in which timely patching can reduce risk. The remaining question is whether exploit code will appear; until then, organizations using TeamViewer control the immediate outcome by installing the fixes the vendor has shipped.

Source: BleepingComputer — TeamViewer urges users to patch severe flaws “as soon as possible”