Cyber Security News

Multiple TeamViewer Vulnerabilities Enable Remote Code Execution Attacks


TeamViewer patched high-severity CVE-2026-16444, allowing authenticated remote-session attackers to write files to unintended locations and potentially execute code with user privileges.

The issue is detailed in TeamViewer security bulletin TV-2026-1008, published on August 26, 2026. It affects TeamViewer Remote, TeamViewer Tensor, and TeamViewer ONE deployments using vulnerable desktop client components.

CVE-2026-16444 stems from improper validation of file paths in TeamViewer Desktop Clients. The application fails to adequately sanitize filenames supplied by a remote peer before creating files on the receiving endpoint.

An authenticated participant in a TeamViewer remote session could exploit path-traversal sequences in filenames sent via the file-transfer function or the virtual file clipboard.

Multiple TeamViewer Vulnerability

Instead of placing a received file only in the intended download directory, the vulnerable client may write it to another location in the local file system. This arbitrary file-write condition can be abused to overwrite or place files in sensitive directories.

If an attacker can write a malicious executable, script, shortcut, or configuration file to a location later accessed by the user or another process, the attack could lead to remote code execution. The vulnerability has a CVSS score of 3.1 (7.5) and is rated Important by TeamViewer.

The exploitation is network-accessible but requires user interaction during a remote session. The flaw affects TeamViewer Full Client, Host, and QuickSupport versions earlier than 15.81.5 on Windows, macOS, and Linux.

Organizations using older supported and legacy releases must also apply the relevant updates. For Windows 7 and Windows 8 systems, affected TeamViewer components should be updated to version 15.64.7 or later.

TeamViewer 14 users should update Windows to 14.7.48833+ and Linux/macOS to 14.7.48838+; version 13 installations are also affected.

Windows systems need version 13.2.36229 or later, Linux systems need 13.2.153978 or later, and macOS systems need version 13.2.153981 or later. Remote-support platforms are attractive targets because they provide access to endpoints across corporate networks.

In this case, exploitation requires the attacker to be an authenticated participant in a TeamViewer session, reducing the likelihood of opportunistic attacks but increasing the risk of compromised accounts, malicious support personnel, or social-engineering operations.

An attacker could exploit the flaw using stolen TeamViewer credentials or an active session to deliver a payload via a seemingly legitimate file transfer.

The ability to write files outside expected directories could also support persistence, data destruction, or privilege-dependent code execution. TeamViewer said it is not aware of any public disclosure before the advisory or of evidence that CVE-2026-16444 has been exploited in the wild.

The company credited researchers Jamir0quai and sam91281 for responsibly reporting the vulnerability through its bug bounty program. Administrators should update all TeamViewer clients, hosts, and QuickSupport installations to version 15.81.5 or the latest available release.

Organizations should also review remote support session logs, restrict file transfers where they are not required, enforce multi-factor authentication, and monitor endpoints for unexpected files written to startup, application, or system paths.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

2 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

2 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

3 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

4 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

4 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

5 hours ago