[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fS9rc79Ehuzp1RnyvAUGzYOLVWBc1x1me3Cj4pAUPK90":3},{"article":4,"iocs":51},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":33,"category":34,"article_tags":38},"c56049b2-5425-4895-b204-20c525a77173","TeamViewer urges users to patch severe flaws “as soon as possible”","teamviewer-urges-users-to-patch-severe-flaws-as-soon-as-possible-8889e8","Remote access software company TeamViewer warned customers on Tuesday to immediately patch a set of high-severity vulnerabilities affecting its client and host software. [...]","TeamViewer has issued an urgent warning for users to patch several high-severity vulnerabilities in its client and host software. The most critical flaw (CVE-2026-92370) allows for remote code execution. While no active exploitation is currently known, the company stresses immediate updates to version 15.82 to mitigate risks, especially given the software's history of being abused by cybercriminals and nation-state actors.","TeamViewer warns users to patch critical vulnerabilities in its client and host software.","TeamViewer urges users to patch severe flaws “as soon as possible” By Sergiu Gatlan September 30, 2026 08:25 AM 0 Remote access software company TeamViewer warned customers on Tuesday to immediately patch a set of high-severity vulnerabilities affecting its client and host software. The highest-severity flaw is a remote session access control bypass (CVE-2026-92370) stemming from an improper access control weakness in TeamViewer Full Client and Host software for Windows, Linux, and macOS that could let remote threat actors perform unauthorized actions leading to remote code execution on targeted systems. The other four security issues addressed on Tuesday are a path traversal (CVE-2026-19743), a heap-based buffer overflow (CVE-2026-92368), a time-of-check time-of-use (TOCTOU) race condition (CVE-2026-92369), and an improper path validation (CVE-2026-92371) that will allow local attackers to gain code execution remotely with the privileges of the current user or escalate privileges to NT AUHORITY\u002FSYSTEM or root. \"TeamViewer strongly recommends that all users update to the latest available version as soon as possible,\" the company warned in a rare advisory urging customers to secure their systems. \"TeamViewer has released security updates addressing multiple vulnerabilities affecting TeamViewer Full Client and Host and related services.\" Although it has not found evidence that the vulnerabilities have publicly available exploit code or are being actively exploited, the company urged customers to update to TeamViewer version 15.82, which addresses these security flaws. \"These vulnerabilities have been resolved in TeamViewer Clients version 15.82 as well as supported maintenance and legacy releases,\" it added. \"TeamViewer is not aware of any public disclosure or active exploitation in the wild.\" While TeamViewer's remote access and desktop sharing software is valued for its simplicity and capabilities, cybercriminals (including ransomware gangs) also often abuse it to access victims' systems remotely and to deploy malware and malicious tools. Over the last decade, TeamViewer has also disclosed several breaches of its corporate network, the first in 2016 linked to Chinese threat actors who used the Winnti backdoor malware and disclosed in May 2019. The second incident affected the company's internal corporate network and was disclosed two years ago. Days later, the breach was linked to a Russian state-backed hacking group tracked as Midnight Blizzard (also known as APT29, Nobelium, Cozy Bear). Build your security blueprint for AI-powered attacks Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed. Save your seat Related Articles: Acronis warns of actively exploited flaw in its cPanel backup pluginGitLab urges users to patch max severity path traversal flawServiceNow warns of three max severity security vulnerabilitiesCISA orders urgent patching of actively exploited Zimbra flawMicrosoft working on Defender patch for ShieldBreak zero-day","https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fteamviewer-urges-users-to-patch-severe-flaws-as-soon-as-possible\u002F","https:\u002F\u002Fwww.bleepstatic.com\u002Fcontent\u002Fhl-images\u002F2026\u002F09\u002F30\u002FTeamViewer_red.jpg","2026-09-30T12:25:10+00:00","2026-09-30T14:00:31.322473+00:00",9,[18,21,24,27,29,31],{"name":19,"type":20},"TeamViewer Full Client and Host","product",{"name":22,"type":23},"TeamViewer","vendor",{"name":25,"type":26},"Midnight Blizzard","threat_actor",{"name":28,"type":26},"APT29",{"name":30,"type":26},"Nobelium",{"name":32,"type":26},"Cozy Bear","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":33,"icon":35,"name":36,"slug":37},null,"Vulnerabilities","vulnerabilities",[39,44,46],{"category":40},{"id":41,"icon":35,"name":42,"slug":43},"6cbdd207-aaa1-4176-9534-e156b125e917","Nation-state","nation-state",{"category":45},{"id":33,"icon":35,"name":36,"slug":37},{"category":47},{"id":48,"icon":35,"name":49,"slug":50},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",[52,56,59,62,65],{"type":53,"value":54,"context":55},"cve","CVE-2026-92370","Remote session access control bypass",{"type":53,"value":57,"context":58},"CVE-2026-19743","Path traversal",{"type":53,"value":60,"context":61},"CVE-2026-92368","Heap-based buffer overflow",{"type":53,"value":63,"context":64},"CVE-2026-92369","Time-of-check time-of-use (TOCTOU) race condition",{"type":53,"value":66,"context":67},"CVE-2026-92371","Improper path validation"]