TeamViewer Issues Urgent Warning Over High-Severity Vulnerabilities Affecting Millions of Users
Remote access software company TeamViewer has issued a stark warning to its customers, urging them to update their systems as soon as possible to prevent potential exploitation of high-severity vulnerabilities. The issue affects the client and host software used by millions worldwide for remote desktop sharing and access.
The most severe flaw, known as CVE-2026-92370, is a remote session access control bypass that allows attackers to perform unauthorized actions on targeted systems, potentially leading to remote code execution. This weakness stems from an improper access control vulnerability in the TeamViewer Full Client and Host software for Windows, Linux, and macOS.
In addition to this critical flaw, four other security issues have been addressed by TeamViewer. These include a path traversal (CVE-2026-19743), a heap-based buffer overflow (CVE-2026-92368), a time-of-check time-of-use (TOCTOU) race condition (CVE-2026-92369), and an improper path validation (CVE-2026-92371). These vulnerabilities can be exploited by local attackers to gain code execution remotely with the privileges of the current user or escalate privileges to NT AUTHORITY/SYSTEM or root.
While TeamViewer has not found evidence that these vulnerabilities have publicly available exploit code or are being actively exploited, the company is taking no chances. In a rare advisory, they urged customers to update to the latest version, 15.82, which addresses these security flaws. “TeamViewer strongly recommends that all users update to the latest available version as soon as possible,” the company warned.
The importance of this warning cannot be overstated. TeamViewer’s remote access and desktop sharing software is widely used for its simplicity and capabilities, but it has also been exploited by cybercriminals in the past. These hackers often abuse TeamViewer to gain unauthorized access to systems and deploy malware or malicious tools. In fact, over the last decade, TeamViewer has disclosed several breaches of its corporate network, including incidents linked to Chinese threat actors and a Russian state-backed hacking group.
With millions of users affected by these high-severity vulnerabilities, it’s essential for those who rely on TeamViewer to take immediate action. Users should update their software as soon as possible to prevent potential exploitation by attackers. This serves as a stark reminder that even widely used software can have significant security implications if not properly maintained and updated.
In light of this warning, it’s crucial for users to regularly review and update their software to ensure they’re protected from the latest threats. By taking proactive steps to secure their systems, users can minimize the risk of exploitation and maintain a safe digital environment.
Source: Bleeping Computer — 2026-09-30