
TeamViewer has issued a rare advisory telling customers to update “as soon as possible” after fixing five high-severity vulnerabilities in its Full Client and Host software for Windows, Linux and macOS. The most serious, CVE-2026-92370, is an improper access control flaw in remote sessions that could let a remote attacker perform unauthorized actions, potentially leading to remote code execution.
The other four are a path traversal (CVE-2026-19743), a heap-based buffer overflow (CVE-2026-92368), a time-of-check time-of-use race condition (CVE-2026-92369) and an improper path validation bug (CVE-2026-92371). These require local access and let an attacker run code as the current user or escalate to SYSTEM or root. TeamViewer says it is not aware of public exploit code or attacks in the wild. Remote-access tools are still a favorite target: ransomware gangs routinely abuse TeamViewer on compromised machines, and the company itself was breached in 2016 and again in 2024.
How to check if you’re affected
Affected versions are TeamViewer Full Client and Host releases older than 15.82, along with supported maintenance and legacy releases that have not received the matching fix. Open TeamViewer, go to Help > About TeamViewer to see your version, and update to 15.82 or the fixed build for your release branch. Organizations should inventory unattended Host installs on servers and unmanaged devices, since those often lag behind, and consider restricting who can connect if patching has to wait.
