Threat Insight
Multiple High-Severity Vulnerabilities in TeamViewer
The remote access software company TeamViewer has warned customers to immediately patch a set of high-severity vulnerabilities affecting its client and host software.
The highest-severity flaw, CVE-2026-92370, is a remote session access control bypass stemming from an improper access control weakness in TeamViewer Full Client and Host software for Windows, Linux, and macOS that could let remote threat actors perform unauthorized actions leading to remote code execution on targeted systems.[1]
Four other security issues have also been addressed, these include CVE-2026-19743 (A path traversal), CVE-2026-92368 (A heap-based buffer overflow), CVE-2026-92369 (A time-of-check time-of-use (TOCTOU) race condition), and CVE-2026-92371 (an improper path validation that will allow local attackers to gain code execution remotely with the privileges of the current user or escalate privileges to NT AUHORITY/SYSTEM or root.)[2]
CVE
CVE-2026-92370
CVE-2026-19743
CVE-2026-92368
CVE-2026-92369
CVE-2026-92371
Affected Products
Versions of TeamViewer Clients prior to 15.82
Recommended Actions
Although there is yet not found evidence that the vulnerabilities have publicly available exploit code or are being actively exploited, TeamViewer has urged customers to update to TeamViewer version 15.82, which addresses these security flaws.
References
[1] https://www.cve.org/CVERecord?id=CVE-2026-92370
[2] https://www.bleepingcomputer.com/news/security/teamviewer-urges-users-to-patch-severe-flaws-as-soon-as-possible/
Stay ahead with cyber insights
Newsletter
Stay ahead in cybersecurity! Sign up for Truesec’s newsletter to receive the latest insights, expert tips, and industry news directly to your inbox. Join our community of professionals and stay informed about emerging threats, best practices, and exclusive updates from Truesec.
Your current browser privacy settings may be preventing this form from loading properly. To continue, please allow cookies/tracking for this site or temporarily disable strict privacy protection, then refresh the page.
If you’re still experiencing issues, please contact us at hello@truesec.com