TeamViewer urges users to patch severe flaws “as soon as possible”

TeamViewer urges users to patch severe flaws “as soon as possible”

Remote access software company TeamViewer warned customers on Tuesday to immediately patch a set of high-severity vulnerabilities affecting its client and host software.

The highest-severity flaw is a remote session access control bypass (CVE-2026-92370) stemming from an improper access control weakness in TeamViewer Full Client and Host software for Windows, Linux, and macOS that could let remote threat actors perform unauthorized actions leading to remote code execution on targeted systems.

The other four security issues addressed on Tuesday are a path traversal (CVE-2026-19743), a heap-based buffer overflow (CVE-2026-92368), a time-of-check time-of-use (TOCTOU) race condition (CVE-2026-92369), and an improper path validation (CVE-2026-92371) that will allow local attackers to gain code execution remotely with the privileges of the current user or escalate privileges to NT AUHORITY/SYSTEM or root.

Read more: bleepingcomputer.com