Heise.De
TeamViewer Patches Critical Code Injection Vulnerabilities
Article Content
TeamViewer has released updates to address two critical vulnerabilities (CVE-2026-16444 and CVE-2026-19042) affecting its desktop clients. CVE-2026-16444 allows authenticated attackers to write files to unintended locations, potentially executing code with user privileges, while CVE-2026-19042 enables remote code execution via malicious URLs sent through chat in the Linux client. Both vulnerabilities were reported through TeamViewer's bug bounty program, and no exploitation in the wild has been confirmed. The vulnerabilities affect TeamViewer Full Client, Host, and QuickSupport across Windows, macOS, and Linux platforms. Users are urged to update to version 15.81.5 or newer to mitigate these risks. The vulnerabilities were published on August 26, 2026, and are classified as high severity with CVSS scores of 7.5 and 8.8, respectively.
Key Points: • Two critical vulnerabilities in TeamViewer patched: CVE-2026-16444 and CVE-2026-19042. • CVE-2026-16444 allows file writing and potential code execution by authenticated attackers. • CVE-2026-19042 enables remote code execution via crafted URLs in Linux chat.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.