Threat reportVulnerabilityTL-2026-2905
Multiple High-Severity Vulnerabilities in TeamViewer Client (CVE-2026-92370, CVE-2026-92368, CVE-2026-92369, CVE-2026-92371, CVE-2026-19743)
Multiple High-Severity Vulnerabilities in TeamViewer Client (TL-2026-2905), also tracked as TV-2026-1010, is a high-severity software vulnerability scored CVSS 8.8, first published 2026-10-02. It has no confirmed attribution, affects TeamViewer TeamViewer Full Client and Host (Windows, Linux, macOS), references 5 CVEs (CVE-2026-92370, CVE-2026-19743, CVE-2026-92368), maps to 4 MITRE ATT&CK techniques (T1133, T1203, T1211), and is covered by 9 detection rules and 12 indicators of compromise.
- CVSS
- 8.8/10High
- CVEs
- 5Referenced vulnerabilities
- Techniques
- 4MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 12Indicators of compromise
Key facts for TL-2026-2905
- Threat ID
- TL-2026-2905
- Also known as
- TV-2026-1010
- Severity
- HIGH
- CVSS
- 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- technology, enterprise, managed services provider, it-support
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 12
Malware and tooling in Multiple High-Severity Vulnerabilities in TeamViewer Client
Malware and tooling: TeamViewer, TeamViewer Full Client, TeamViewer Host
How Multiple High-Severity Vulnerabilities in TeamViewer Client works
TeamViewer security bulletin TV-2026-1010 (29 Sep 2026) fixes five high-severity flaws in the Full Client and Host, led by CVE-2026-92370 (CVSS 8.8), a remote session access-control bypass that can lead to remote code execution. The other four are local privilege-escalation or memory-corruption bugs. All are fixed in version 15.82, and TeamViewer is not aware of public disclosure or active exploitation.
TeamViewer published security bulletin TV-2026-1010 on 29 September 2026 (no later update). It covers five CVEs in the TeamViewer Full Client and Host. Per the bulletin, the researchers who reported them are unnamed and were credited generically under coordinated vulnerability disclosure. Product-line coverage in the press names TeamViewer Remote, Tensor and ONE. BleepingComputer covered the bulletin on 30 September and Truesec summarised it on 2 October 2026. All five are fixed in 15.82, and TeamViewer urges users to update as soon as possible.
CVE-2026-92370 (CVSS 3.1 8.8, AV:N/AC:L/PR:N/UI:R, CWE-284) is the most serious. It is an improper access control flaw in the Full Client, Host and related modules on Windows, Linux and macOS. A remote attacker can bypass user-configured permission settings during session establishment. By modifying access-control parameters for restricted features, the attacker can perform actions the victim's configuration explicitly denies. Truesec and BleepingComputer describe the outcome as unauthorized actions and remote code execution on the targeted system. Affected versions are everything before 15.82, plus the legacy branches 15.64, 14.7 and 13.2.
CVE-2026-19743 (CVSS 7.8, AV:L/AC:L/PR:L/UI:N, CWE-22) is improper path validation (path traversal) in the local IPC service of the Full Client and Host on Windows, Linux and macOS. A local low-privileged user can send crafted IPC commands to the service and manipulate file paths. This gives arbitrary file writes with elevated privileges (NT AUTHORITY\SYSTEM or root), i.e. local privilege escalation. Versions before 15.82 are affected, as are legacy branches 15.64, 14.7 and 13.2 (Windows/Linux).
CVE-2026-92368 (CVSS 7.8, AV:L/AC:L/PR:L/UI:N, CWE-122) is a heap-based buffer overflow in the processing of .tvs session recording files on Linux and macOS only, in versions 15.70 up to but not including 15.82. A size mismatch during decompression can cause out-of-bounds heap writes. Media coverage describes the impact as local code execution with the current user's privileges, with some outlets also citing escalation to SYSTEM/root.
CVE-2026-92369 (CVSS 7.3, AV:L/AC:L/PR:L/UI:R, CWE-367) is a TOCTOU race condition in the Windows installer rollback mechanism. A low-privileged attacker can replace rollback backup files in a user-writable temporary directory before the elevated installer restores them, which gives privilege escalation. Versions before 15.82 on Windows are affected, plus legacy branches 15.64, 14.7 and 13.2.
CVE-2026-92371 (CVSS 7.0, AV:L/AC:H/PR:L/UI:N, CWE-59) is an improper path validation / link resolution flaw in the Cloud Session Recording functionality, Linux only, in versions 15.0 up to but not including 15.82. A race between path validation and file access lets a local authenticated attacker cause privileged file operations in unintended locations, which is local privilege escalation to root.
TeamViewer states it is not aware of any public disclosure or active exploitation in the wild. No source reports public exploit code, attribution or network IOCs, and the vendor bulletin publishes no detection guidance. Context: TeamViewer is widely deployed remote-access software that has previously been abused by threat actors and was itself breached (a 2016 intrusion linked to Chinese actors using Winnti malware, disclosed in May 2019, and a 2024 intrusion attributed to Midnight Blizzard / APT29). Defenders should prioritise patching, inventory legacy branches, and monitor for anomalous TeamViewer sessions and permission changes.
MITRE ATT&CK techniques used in TL-2026-2905
Initial Access
T1133 External Remote Services
Execution
T1203 Exploitation for Client Execution
Stealth
T1211 Exploitation for Stealth
Command and Control
Affected products and versions in Multiple High-Severity Vulnerabilities in TeamViewer Client
- TeamViewer — TeamViewer Full Client and Host (Windows, Linux, macOS)
Vulnerable versions: < 15.82 (CVE-2026-92370, CVE-2026-19743); 15.64 legacy; 14.7 legacy; 13.2 legacy
Fixed in: 15.82 - TeamViewer — TeamViewer Full Client and Host for Windows (installer rollback)
Vulnerable versions: < 15.82 (CVE-2026-92369); 15.64, 14.7, 13.2 legacy
Fixed in: 15.82 - TeamViewer — TeamViewer Full Client and Host for Linux and macOS (.tvs session recording)
Vulnerable versions: 15.70 to < 15.82 (CVE-2026-92368)
Fixed in: 15.82 - TeamViewer — TeamViewer Full Client and Host for Linux (Cloud Session Recording)
Vulnerable versions: 15.0 to < 15.82 (CVE-2026-92371)
Fixed in: 15.82 - TeamViewer — TeamViewer Remote, TeamViewer Tensor, TeamViewer ONE
Vulnerable versions: Full Client/Host < 15.82
Fixed in: 15.82
Remediation for Multiple High-Severity Vulnerabilities in TeamViewer Client
Patches
- TeamViewer 15.82 fixes CVE-2026-92370, CVE-2026-92368, CVE-2026-92369, CVE-2026-92371 and CVE-2026-19743 (bulletin TV-2026-1010)
Immediate actions
- Update TeamViewer Full Client and Host to version 15.82 or the latest available release on all Windows, Linux and macOS endpoints
- Inventory all TeamViewer installs, including legacy branches 15.64, 14.7 and 13.2, and upgrade any that are still deployed
Workarounds
- The bulletin lists no workaround; updating is the stated remediation
- Where patching is delayed, uninstall or disable TeamViewer on systems that do not need remote access
Longer-term hardening
- Restrict TeamViewer to approved endpoints and enforce allow-lists and managed policies for remote-access software
- Monitor TeamViewer session establishment and permission changes, and alert on unexpected remote sessions
- Limit local low-privileged user access on shared Linux and Windows hosts that run TeamViewer
- Restrict write access to temporary directories used by installers and block untrusted .tvs session recording files on Linux and macOS
CVEs associated with Multiple High-Severity Vulnerabilities in TeamViewer Client
CVE-2026-92370, CVE-2026-19743, CVE-2026-92368, CVE-2026-92369, CVE-2026-92371
Weaknesses (CWE) in Multiple High-Severity Vulnerabilities in TeamViewer Client
Timeline of Multiple High-Severity Vulnerabilities in TeamViewer Client
- Context: TeamViewer's corporate network is breached in 2016 by actors linked to China using Winnti malware (not disclosed until May 2019); exact date unspecified in source, placed at year start
- Context: TeamViewer's internal corporate network breach attributed to Russian state-backed Midnight Blizzard (APT29); source gives only the year 2024, date is an approximation
- Vendor states it is not aware of any public disclosure or active exploitation in the wild and credits unnamed researchers under coordinated disclosure
- Vendor rates the issues CVSS 3.1 7.0-8.8 (High); CVE-2026-92370 (8.8) is the highest, enabling a remote access-control bypass and RCE
- TeamViewer 15.82 released as the fixed version for all five vulnerabilities in the Full Client and Host
- TeamViewer issues security bulletin TV-2026-1010 covering CVE-2026-92370, CVE-2026-92368, CVE-2026-92369, CVE-2026-92371 and CVE-2026-19743; no later update recorded
- BleepingComputer reports that TeamViewer urges users to patch as soon as possible, listing all five CVEs and repeating the no-exploitation statement
- Truesec publishes a summary of the multiple high-severity TeamViewer vulnerabilities and recommends updating to 15.82; no IOCs or detection guidance provided
Sources cited for Multiple High-Severity Vulnerabilities in TeamViewer Client
- Multiple High-Severity Vulnerabilities in TeamViewer (Truesec)
- TeamViewer Security Bulletin TV-2026-1010
- TeamViewer urges users to patch severe flaws as soon as possible (BleepingComputer)
- TeamViewer patches five critical flaws, urges immediate update to 15.82
- TeamViewer: five vulnerabilities, immediate update (secnews.gr)
- CVE Record CVE-2026-92370
Detection coverage for TL-2026-2905
As of 2026-10-02, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2905 across Splunk SPL, Microsoft KQL and Sigma, covering 12 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.