As reported by BleepingComputer, TeamViewer has issued an urgent advisory urging customers to patch five high-severity vulnerabilities affecting its Full Client and Host software across Windows, Linux, and macOS. The most concerning flaw — CVE-2026-92370 — is an improper access control weakness that could allow remote threat actors to bypass session controls and achieve remote code execution. The remaining four CVEs enable local privilege escalation to NT AUTHORITY\SYSTEM or root.

Security Impact: As reported by BleepingComputer, TeamViewer has issued an urgent advisory urging customers to patch five high-severity vulnerabilities affecting its Full Client and Host software across Windows, Linux, and macOS.

Vulnerability Breakdown

CVETypeImpactVector
CVE-2026-92370Improper Access Control / Session BypassRemote Code ExecutionRemote
CVE-2026-19743Path TraversalCode Execution with current user privilegesLocal
CVE-2026-92368Heap-based Buffer OverflowCode Execution with current user privilegesLocal
CVE-2026-92369TOCTOU Race ConditionPrivilege Escalation to SYSTEM/rootLocal
CVE-2026-92371Improper Path ValidationPrivilege Escalation to SYSTEM/rootLocal

All vulnerabilities are rated High severity. TeamViewer reports no evidence of active exploitation or public proof-of-concept code at this time. Patches are available in TeamViewer version 15.82 for supported releases, with maintenance and legacy branches also updated.

Why This Matters More Than a Typical Patch Tuesday

Remote access tools are a privileged target class. They run with elevated trust, maintain persistent outbound connections, and are frequently deployed on endpoints that operators rarely audit. CVE-2026-92370 is particularly significant: a session access control bypass in a remote support product is functionally an attacker's dream — it eliminates the need for credentials or social engineering to establish a foothold.

The local privilege escalation flaws should not be dismissed as secondary. In environments where TeamViewer runs under SYSTEM or as a persistent service — which is the default for Host deployments on helpdesk-managed machines — a local compromise chained with CVE-2026-92369 or CVE-2026-92371 yields full system takeover. Industrial OT workstations, kiosks, and shared clinical terminals are prime targets for this attack pattern.

Historical Risk Context

TeamViewer carries outsized risk exposure for two reasons. First, ransomware affiliates have long abused legitimate remote access tools to pivot post-compromise, and TeamViewer is among the most frequently observed in incident response engagements. Second, TeamViewer's own corporate network has been breached multiple times — notably by APT29 (Midnight Blizzard) in 2024 — raising legitimate concerns about supply chain risk if attacker infrastructure were ever used to push malicious updates or harvest deployment telemetry.

If your organization allows TeamViewer anywhere in the environment, treat this advisory as a critical-week patch event — not a standard quarterly cycle item.

Shield53 Recommendations: Immediate Actions

Shield53 Recommendations: Immediate Actions
Patch to 15.82 immediately on all Full Client and Host deployments across Windows, macOS, and Linux. Do not wait for maintenance windows.
Audit deployment inventory: Use endpoint detection or asset management tooling to enumerate every TeamViewer installation, including legacy versions that may not auto-update. Identify any unmanaged or shadow IT instances.
Restrict outbound TeamViewer traffic at the network perimeter if the tool is not operationally required. Consider allowlisting specific TeamViewer account IDs rather than permitting all connections.
Harden Host configurations: Enforce two-factor authentication, disable Easy Access where not strictly required, and confirm password complexity policies are active on all managed accounts.
Deploy detection rules for post-exploitation indicators: unexpected child processes spawned by the TeamViewer service, new outbound connections from non-standard accounts, and PowerShell or WMI activity originating from the TeamViewer process tree.
Review session logs for the past 30 days for anomalies — off-hours connections, connections from unexpected geographies, or sessions to sensitive hosts that have no documented support ticket.

Who Is Most At Risk

  • MSPs and IT service providers running TeamViewer Host on all managed customer endpoints.
  • Healthcare and manufacturing environments with shared terminals running under elevated service accounts.
  • Organizations with legacy TeamViewer versions still in production — these are now unpatched against known high-severity flaws.

The absence of public PoCs or confirmed exploitation is a temporary condition, not a guarantee. Historically, high-severity remote access tool vulnerabilities attract rapid attention from both research and criminal communities. The window between disclosure and weaponization is shrinking — act now.