Skip to content

Security1 publisher2 min readPublished

Remote access-control bypass tops five TeamViewer flaws fixed in version 15.82

TeamViewer urged users to install version 15.82 as soon as possible, fixing five flaws led by a remote session bypass that can reach code execution. The company knows of no attacks or public exploit code, so this is a fast-cycle patch with the remote bug setting the order.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying Remote access-control bypass tops five TeamViewer flaws fixed in version 15.82
Generated illustration

What happened

  • The remote flaw, CVE-2026-92370, is an improper access control bug in TeamViewer Full Client and Host on Windows, Linux and macOS.
  • The other four, a path traversal, a heap overflow, a race condition and a path validation bug, let a local attacker run code as the current user or escalate to SYSTEM or root.
  • Supported maintenance and legacy releases received the same fixes as the 15.82 client line.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Host installs are in scope alongside Full Client ones on Linux and Mac as well as Windows, so an inventory limited to Windows endpoints will miss machines that need the update.
  • capability On any machine where an intruder already runs code as a normal user, an unpatched TeamViewer is a documented route to SYSTEM or root.
  • decision With four of five bugs gated on local access and no known exploitation, CVE-2026-92370 alone is the reason to move TeamViewer ahead of the normal patch cycle.

"TeamViewer strongly recommends that all users update to the latest available version as soon as possible," the company wrote [4]. BleepingComputer reported the warning on Tuesday and called it a rare advisory [1][5]. The advisory says the updates address vulnerabilities "affecting TeamViewer Full Client and Host and related services." [12]

The open question is what CVE-2026-92370 needs before it fires. BleepingComputer's account does not say whether an attacker needs an established session or valid credentials to trigger it. The only severity label it gives the set is "high-severity" [1][2].

The vendor's statement on exploitation is short: "TeamViewer is not aware of any public disclosure or active exploitation in the wild." [7] Criminal crews, ransomware gangs among them, often abuse TeamViewer to reach victims' machines and deploy malware and tools, according to BleepingComputer [11]. In those cases the software does what it was built to do [11]. The five CVEs are a different problem. They are flaws that let an attacker go past what an install is supposed to allow [2][3].

The company has also been a target of state groups [9][10]. Chinese threat actors using the Winnti backdoor breached its corporate network in 2016, and TeamViewer disclosed that breach in May 2019 [9]. A second intrusion, into its internal corporate network, was disclosed two years ago. Days later it was linked to Midnight Blizzard, the Russian state-backed group also tracked as APT29 and Cozy Bear [10].

What to watch

  • Technical detail from TeamViewer or a researcher on whether CVE-2026-92370 needs an authenticated session or valid credentials.
  • Public proof-of-concept code or a first confirmed exploitation report for any of the five CVEs.
  • Whether TeamViewer names the 'related services' its advisory says the updates also cover.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories