TeamViewer warned users to urgently patch multiple high-severity vulnerabilities in TeamViewer Full Client and Host software for Windows, Linux, and macOS, including a remote session access control bypass that could lead to remote code execution. The company said it is not aware of active exploitation, but urged immediate updating to TeamViewer version 15.82 to reduce the risk of unauthorized access and privilege escalation. #TeamViewer #CVE-2026-92370 #CVE-2026-19743 #CVE-2026-92368 #CVE-2026-92369 #CVE-2026-92371 #Winnti #MidnightBlizzard
Keypoints
- TeamViewer released security updates for multiple high-severity flaws in its client and host software.
- The most serious issue is CVE-2026-92370, an access control bypass that could enable remote code execution.
- Additional flaws include path traversal, heap-based buffer overflow, TOCTOU race condition, and improper path validation.
- The bugs could allow attackers to execute code locally or elevate privileges to SYSTEM or root.
- TeamViewer urges all users to update to version 15.82, with no evidence of public exploits or active abuse so far.