HomeTopics 1Application SecurityTeamViewer Fixes Five High-Severity Vulnerabilities, Including Remote Code Execution Risk

TeamViewer Fixes Five High-Severity Vulnerabilities, Including Remote Code Execution Risk

Date:

Related stories

spot_imgspot_imgspot_imgspot_img

TeamViewer has released security updates for five vulnerabilities affecting its Full Client and Host software across Windows, Linux and macOS, including a high-severity flaw that could allow an authenticated remote attacker to bypass configured access controls and potentially execute code on a target system.

The vulnerabilities were disclosed in TeamViewer security bulletin TV-2026-1010, published on September 29, 2026. The company rates the bulletin as “Important”, with vulnerabilities reaching a CVSS 3.1 score of 8.8.

TeamViewer says the vulnerabilities have been fixed in version 15.82 and corresponding supported maintenance and legacy releases. It also says it is not aware of public disclosure or active exploitation of the vulnerabilities in the wild at the time of publication.

For organizations that rely on TeamViewer for remote IT support, administration, monitoring or operational access, however, the advisory deserves prompt attention. Remote-access software sits close to some of the most sensitive parts of an enterprise environment. A weakness in the client or host can therefore have consequences beyond the workstation where the software is installed.

Five vulnerabilities, different attack paths

The five vulnerabilities do not represent a single attack technique. They affect different components and functions of TeamViewer, with some requiring local access while another potentially exposes remote-session controls.

The most severe issue is CVE-2026-92370, an improper access-control vulnerability affecting TeamViewer Full Client, Host and related modules on Windows, Linux and macOS.

Rated CVSS 8.8, the vulnerability can allow an authenticated remote attacker to bypass user-configured permission restrictions during session establishment. According to TeamViewer, an attacker could modify access-control parameters for restricted features and perform actions that the victim had explicitly denied. Under certain circumstances, this could ultimately result in remote code execution.

That distinction matters. Remote-access security depends heavily on the permissions configured by administrators and users. If those controls can be bypassed, an organization may lose an important layer of protection even when its TeamViewer policies appear correctly configured.

A second vulnerability, CVE-2026-19743, is a path-traversal flaw in the local inter-process communication service of TeamViewer Full Client and Host. Rated 7.8, it can allow a low-privileged local authenticated user to manipulate file paths and write files with elevated privileges, potentially reaching NT AUTHORITY\SYSTEM on Windows or root privileges on Linux and macOS.

CVE-2026-92368, also rated 7.8, affects TeamViewer’s handling of .tvs session recording files on Linux and macOS. A specially crafted recording could trigger a heap-based buffer overflow during playback and potentially lead to arbitrary code execution with the privileges of the current user. The attack requires convincing a user to open the malicious recording through the session playback or conversion functionality.

CVE-2026-92369 affects the Windows installer rollback mechanism. The 7.3-rated vulnerability involves a time-of-check-to-time-of-use race condition that could allow a low-privileged local attacker to replace rollback files in a writable temporary directory before an elevated installer restores them. Successful exploitation requires the attacker to win a timing race during an installation or update rollback.

The fifth vulnerability, CVE-2026-92371, affects Cloud Session Recording functionality on Linux. Rated 7.0, it involves improper link resolution and a race condition that could allow a local authenticated attacker to cause privileged file operations in unintended locations.

What versions are affected?

TeamViewer says Full Client and Host versions below 15.82 are affected across Windows, Linux and macOS.

Organizations running older supported or legacy releases also need to check their environments carefully. The advisory identifies maintenance and legacy branches including TeamViewer 15.64 for Windows 7 and 8, version 14.7 and version 13.2, with specific patched releases provided by the vendor.

This is particularly important in environments where older operating systems or legacy TeamViewer installations remain in service. Simply updating the newest endpoints may not be enough if older versions are still deployed on servers, engineering workstations, production systems or remote-support machines.

Why remote-access vulnerabilities deserve attention

Remote administration tools have become a normal part of modern IT operations. Help desks use them to troubleshoot employee devices, IT teams use them to manage distributed infrastructure, and service providers may use them to support customer environments.

That convenience also makes remote-access software an attractive security boundary.

A compromised remote-access client can provide visibility or control that traditional endpoint vulnerabilities may not. Depending on how the software is configured, the affected machine could provide access to business applications, credentials, internal systems or sensitive data.

The TeamViewer advisory does not say that attackers are currently exploiting these vulnerabilities. In fact, TeamViewer explicitly states that it is not aware of public disclosure or active exploitation in the wild.

That should nevertheless be treated as a current status statement, not as a reason to postpone remediation.

For security teams, the sensible response is to establish where vulnerable versions exist, update them, verify that the updates were successful and review the surrounding remote-access controls.

The issue also reinforces a broader security principle: remote-access platforms should be treated as privileged infrastructure rather than ordinary desktop applications.

MEA organizations should take note

The advisory is globally relevant, including for organizations across the Middle East and Africa.

Enterprises, banks, government agencies, telecommunications providers, energy companies, mining operations, healthcare organizations and managed service providers increasingly depend on remote administration to support geographically distributed environments.

In many MEA organizations, remote support can also bridge multiple offices, contractors, regional operations and third-party service providers. That makes asset visibility and consistent patching particularly important.

A vulnerable TeamViewer installation that has been forgotten on a remote endpoint can remain an overlooked entry point long after the original deployment team has moved on.

Security teams should therefore include remote-access software in routine vulnerability management and asset inventories, alongside operating systems, browsers, VPN clients, firewalls and other externally connected technologies.

This is consistent with the broader security lesson highlighted in our previous coverage of exposed network infrastructure in the UAE: organizations need visibility into the systems and applications that can become accessible from outside their intended security boundaries.

10 actions security teams should take now

  1. Inventory every TeamViewer installation

Identify all Full Client and Host deployments across Windows, Linux and macOS. Do not rely solely on software inventories; check remote endpoints, servers and machines managed by external IT teams as well.

  1. Confirm the installed version

Prioritize systems running versions below 15.82. Also identify legacy installations and verify whether the appropriate maintenance release has been installed.

  1. Patch to the latest available release

TeamViewer’s primary mitigation is straightforward: update to version 15.82 or the latest available version.

  1. Pay particular attention to remote-access hosts

Hosts that remain permanently available for remote connections should receive particular scrutiny. Confirm that their software is patched and that the systems themselves are still required.

  1. Review TeamViewer permissions

The CVE-2026-92370 access-control issue is a reminder to review permissions rather than assuming they provide complete protection. Remove unnecessary capabilities and apply least-privilege principles wherever possible.

  1. Check session-recording functionality

On Linux and macOS, review the use of .tvs session recordings and Cloud Session Recording. Until vulnerable systems are updated, organizations should be cautious about opening untrusted recording files.

  1. Review legacy systems

Search specifically for old TeamViewer versions installed on Windows 7/8 systems or other systems that may have been excluded from normal patch-management processes.

  1. Monitor authentication and remote-session activity

Review logs for unusual TeamViewer connections, unexpected administrative activity, new remote sessions or access originating from unusual locations.

  1. Integrate remote-access software into vulnerability management

TeamViewer should not be treated as an isolated application. Include remote-access technologies in regular vulnerability scanning, asset discovery, patch compliance and security-risk reporting.

  1. Train users and administrators

Technical controls work best when users understand the risks. Security awareness and professional cybersecurity training should cover malicious files, remote-support abuse, suspicious session requests and the secure use of remote administration tools.

Organizations looking to strengthen their broader cybersecurity posture can also assess areas such as vulnerability management, GRC, endpoint security, identity and access management, SOC monitoring and cybersecurity certification training through Saintynet Cybersecurity.

The bigger lesson: remote access needs continuous oversight

The TeamViewer vulnerabilities illustrate why remote-access platforms deserve the same security attention as other privileged technologies.

The risk is not limited to whether an attacker can exploit a particular software flaw. Organizations also need to consider who can initiate remote sessions, what those users can access, which permissions are enabled, how sessions are monitored and whether old installations remain connected to the environment.

For security leaders, this is ultimately an asset-management and access-control problem as much as it is a patching problem.

TeamViewer has already released fixes for the five vulnerabilities covered by TV-2026-1010, and the company recommends updating as soon as possible. Organizations should use the advisory as an opportunity to identify every TeamViewer deployment in their environment, bring vulnerable systems up to date and review the controls surrounding remote administration.

There is currently no indication from TeamViewer of active exploitation in the wild. But for software that can provide remote control of enterprise systems, waiting for exploitation before taking action is an unnecessary risk.

Source: TeamViewer Security Bulletin TV-2026-1010, published September 29, 2026.

Subscribe

- Never miss a story with notifications

- Gain full access to our premium content

- Browse free from up to 5 devices at once

Latest stories

spot_imgspot_imgspot_imgspot_img