TeamViewer has released fixes for two high-severity Desktop Client vulnerabilities: CVE-2026-19042, a Linux command-injection issue, and CVE-2026-16444, an improper path-validation flaw. CVE-2026-19042 can enable remote code execution after a Linux user clicks an attacker-crafted URL sent through out-of-session chat. CVE-2026-16444 allows an authenticated participant in a remote session to use path-traversal sequences in file-transfer or virtual-file-clipboard filenames to write files outside the intended download directory.
The arbitrary file-write flaw could allow attackers to place or overwrite executables, scripts, shortcuts, or configuration files and potentially execute code with the affected user's privileges. Affected deployments include TeamViewer Remote, Tensor, and ONE using vulnerable Full Client, Host, or QuickSupport components on Windows, macOS, and Linux. Organizations should update clients to version 15.81.5 or later, apply the available legacy-branch fixes, and instruct Linux users awaiting patches not to open links received through TeamViewer chat; TeamViewer reported no known public disclosure or in-the-wild exploitation before its advisory.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
TeamViewer published security bulletin TV-2026-1008 addressing CVE-2026-16444, an improper file-path validation flaw that lets an authenticated remote-session participant use file transfer or the virtual clipboard to write files outside the intended directory. The company recommended updating affected Desktop Client components and stated it knew of no prior public disclosure or in-the-wild exploitation.
TeamViewer released updates for CVE-2026-19042, a high-severity command-injection vulnerability affecting TeamViewer Full Client and Host for Linux. An attacker could send a crafted URL in a TeamViewer chat message and execute commands in the victim user's context if the recipient clicked it; version 15.81.5 and later fixes the issue.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
heise.de
Open sourcecybersecuritynews.com
Open sourcesecurityonline.info
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.