Remote access software company TeamViewer has warned customers to immediately update its client and host software after disclosing five high-severity vulnerabilities affecting TeamViewer Full Client and Host on Windows, Linux and macOS.

The most serious flaw, tracked as CVE-2026-92370, is an improper access control vulnerability that can allow remote attackers to bypass remote session access controls and perform unauthorized actions. The issue could ultimately lead to remote code execution on affected systems.

The other four vulnerabilities include a path traversal flaw tracked as CVE-2026-19743, a heap-based buffer overflow tracked as CVE-2026-92368, a time-of-check time-of-use (TOCTOU) race condition tracked as CVE-2026-92369, and an improper path validation issue tracked as CVE-2026-92371. According to TeamViewer, the flaws could allow local attackers to execute code with the privileges of the current user or escalate privileges to NT AUTHORITY\SYSTEM on Windows or root on Linux and macOS.

“TeamViewer strongly recommends that all users update to the latest available version as soon as possible,” the company said in a security advisory. TeamViewer said it has released updates addressing multiple vulnerabilities affecting its Full Client, Host and related services.

The vulnerabilities have been fixed in TeamViewer version 15.82, along with supported maintenance and legacy releases. The company said it is not aware of publicly available exploit code or active exploitation of the vulnerabilities in the wild.

Despite the absence of known exploitation, the vulnerabilities are significant because TeamViewer provides remote access to systems and is widely used for remote support and administration. Cybercriminals, including ransomware groups, have also previously abused TeamViewer to gain remote access to victims’ networks and deploy malware and other malicious tools.

READ
Tor Releases Emergency Security Update for High-Severity Vulnerabilities

TeamViewer has also disclosed security incidents involving its corporate network in the past. A 2016 incident was later linked to Chinese threat actors who used Winnti backdoor malware, while another breach disclosed two years ago affected the company’s internal corporate network and was later attributed to the Russian state-backed group Midnight Blizzard, also known as APT29, Nobelium and Cozy Bear.


Buy ExpressVPN with PayPal or Credit Card

Users running affected TeamViewer versions should update to version 15.82 or an applicable supported maintenance or legacy release as soon as possible to address the vulnerabilities.

Advertisement