TeamViewer released fixes for five high-severity vulnerabilities in its Full Client and Host products for Windows, Linux, and macOS. The issues primarily affect versions earlier than 15.82 and include local privilege-escalation flaws, a heap-based buffer overflow in session-recording playback that could enable code execution, and an access-control bypass that could allow unauthorized remote actions and potentially remote code execution.
The Canadian Centre for Cyber Security issued advisory AV26-977 urging organizations to review TeamViewer’s security bulletins and apply available updates. TeamViewer said version 15.82, along with specified maintenance and legacy releases, remediates the flaws; it reported no known public disclosure or active exploitation at the time of publication. Organizations should prioritize updating TeamViewer endpoints, especially systems that permit unattended remote access or use session recording.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
The Canadian Centre for Cyber Security issued advisory AV26-977 concerning multiple vulnerabilities affecting TeamViewer Full Client and Host on Windows, Linux, and macOS. It advised users and administrators to review TeamViewer security information and apply available updates.
TeamViewer released updates for five high-severity flaws affecting TeamViewer Full Client, Host, and related modules, including local privilege-escalation, session-recording buffer-overflow, and access-control-bypass issues. The company recommended updating to version 15.82 or the latest supported release and stated it knew of no public disclosure or active exploitation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcecyber.gc.ca
Open sourceteamviewer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.