Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
TeamViewer released a cumulative security update on September 30, 2026, addressing five high-severity vulnerabilities in its Full Client and Host software for Windows, Linux, and macOS. The vendor urged users to update "as soon as possible," a phrasing rarely used by the company that — combined with the software's profile as a remote-access vehicle — signals an internal impact assessment above the norm for its standard advisories. None of the five flaws are known to be actively exploited at the time of disclosure.
- Five high-severity CVEs affect TeamViewer Full Client and Host on Windows, Linux, and macOS, with combined remote and local impact
- CVE-2026-92370 (CVSS 8.8) enables session-permission bypass via improper access control, with potential remote code execution
- CVE-2026-92369 (CVSS 7.3) exploits a TOCTOU race condition in the Windows installer to elevate privileges to SYSTEM
- Corrective version 15.82 also covers legacy and maintenance releases, with patches extended to prior versions such as 15.64.x and 14.7.x
The Remote Core: When Access Becomes Execution
The most severe vulnerability in the set, CVE-2026-92370, carries a CVSS 8.8 score per TheHackerWire and a CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H vector per the NVD record. The flaw resides in an improper access control (CWE-284) in the remote session setup: an attacker can modify ACL parameters for restricted functions, bypassing user-configured permissions and opening a path to remote code execution.
The attack vector presents a documented ambiguity in the dossier. NVD describes an "authenticated remote attacker," while BleepingComputer reports "remote threat actors" without specifying an authentication requirement. The source does not clarify whether authentication is required for initial exploitation or only for session interaction. This gap has concrete operational implications: if authentication is mandatory, the attack surface narrows to compromised sessions or stolen credentials; if absent, the vulnerability becomes wormable on exposed systems.
The network attack vector (AV:N) and low attack complexity (AC:L) confirm the flaw is exploitable without prohibitive conditions. Impact on confidentiality, integrity, and availability is rated "high" across all three CIA pillars, meaning a successful exploit fully compromises the target system.
The Local Perimeter: Three Paths to SYSTEM and root
The remaining four CVEs complete a heterogeneous risk profile across platforms and mechanisms. CVE-2026-19743 is a path traversal vulnerability (CWE-22) allowing arbitrary file write with elevated privileges, scoped to Windows, Linux, and macOS per the NVD record. CVE-2026-92368 is a heap-based buffer overflow (CWE-122) in parsing .tvz session-recording files, limited to Linux and macOS.
CVE-2026-92369 exploits a Time-of-Check to Time-of-Use race condition (CWE-367, CVSS 7.3 per TheHackerWire) in the Windows installer. The flaw allows a local attacker with limited privileges to manipulate files between verification and opening, elevating rights to SYSTEM. The AV:L/AC:L/PR:L/UI:R vector indicates the attack requires user interaction — typically executing a malicious or modified installer — but no elevated initial privileges.
CVE-2026-92371 affects only Linux via improper path validation (CWE-59) in the Cloud Session Recording feature. The NVD record indicates the vulnerability is not prioritized for NVD enrichment, which may slow the availability of additional technical details.
For CVE-2026-19743, CVE-2026-92368, and CVE-2026-92371, the dossier does not report numerical CVSS scores from the extracted NVD records. The records are marked "not being prioritized for NVD enrichment" for at least two of these CVEs, a practice that reduces public visibility into severity and exploit conditions.
The Vendor's Urgency and What It Signals
"TeamViewer strongly recommends that all users update to the latest available version as soon as possible" — TeamViewer advisory, reported by BleepingComputer
The "as soon as possible" formulation is a rare element in TeamViewer communications. The dossier provides no comparative metrics against the vendor's prior advisories, but the lexical choice aligns with an observable pattern among remote-access software makers: when the same infrastructure that enables legitimate control can be turned against the system, the temporal tolerance margin evaporates.
TeamViewer explicitly stated it is not "aware of any public disclosure or active exploitation in the wild." The phrasing, reported by BleepingComputer, rules out known exploits but does not reduce the likelihood of future weaponization. The software has historically been a prime target for ransomware groups that abuse it as an initial-access or persistence vector: the Midnight Blizzard/APT29 incident and the 2016 Winnti malware compromise are documented in the sources as relevant precedents for the vendor's risk profile.
Why It Matters
The dossier does not specify alternative mitigations to patching, nor does it list temporary compensating controls. The source does not clarify whether disabling specific features — such as Cloud Session Recording on Linux or .tvz file parsing — can partially mitigate risk pending the update. The cited advisory also does not document the identity of the researchers who discovered the vulnerabilities or the involvement of a bug-bounty program in the disclosure.
Corrective version 15.82 is available for current releases; NVD lists patches extended to legacy versions 15.64.0→15.64.8, 14.7.0→14.7.48855, and 13.2.0→13.2.36230. The retroactive coverage suggests a significant affected installed base, but the dossier does not quantify the number of vulnerable endpoints. TeamViewer has not provided a timeline for discovery of the flaws: the known disclosure date is September 29–30, 2026, with no indication of when the vendor was notified or began developing fixes.
The absence of public exploits is a transient state. For software with such a broad enterprise and consumer install base, the publication of technical details in NVD records — including CVSS vectors and CWEs — gives threat actors the components to reverse-engineer the vulnerabilities. The gap between disclosure and mass weaponization, when it occurs, is typically days or weeks, not months.
The combination of a remote vector with RCE impact and multiple local privilege-escalation paths constitutes a plausible exploit chain: initial access via manipulated session, elevation to SYSTEM/root, persistence, and lateral movement. This scenario is not a remote hypothesis but a standard risk profile for remote-access software, and it explains why the vendor forced urgency language even without confirmed exploitation.
Sources
- https://www.bleepingcomputer.com/news/security/teamviewer-urges-users-to-patch-severe-flaws-as-soon-as-possible/
- https://radar.offseq.com/threat/teamviewer-urges-users-to-patch-severe-flaws-as-soon-as-possible-ebf6971802c54bd2
- https://blog.netmanageit.com/teamviewer-urges-users-to-patch-severe-flaws-as-soon-as-possible/
- https://www.thehackerwire.com/vulnerability/CVE-2026-92370/
- https://www.thehackerwire.com/vulnerability/CVE-2026-92369/
- https://nvd.nist.gov/vuln/detail/CVE-2026-92370
- https://nvd.nist.gov/vuln/detail/CVE-2026-19743
- https://nvd.nist.gov/vuln/detail/CVE-2026-92368
- https://nvd.nist.gov/vuln/detail/CVE-2026-92369
- https://nvd.nist.gov/vuln/detail/CVE-2026-92371
Information is based on the cited source and current as of publication.
Sources
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.