TeamViewer Patches Critical Code Injection Vulnerabilities

TeamViewer Patches Critical Code Injection Vulnerabilities

First seen 28 Aug 2026, 14:23 UTC CybersecuritynewsHeise.Dewww.teamviewer.com 64.5

Article Content

Browse articles
ThreatCluster

TeamViewer has released updates to address two critical vulnerabilities (CVE-2026-16444 and CVE-2026-19042) affecting its desktop clients. CVE-2026-16444 allows authenticated attackers to write files to unintended locations, potentially executing code with user privileges, while CVE-2026-19042 enables remote code execution via malicious URLs sent through chat in the Linux client. Both vulnerabilities were reported through TeamViewer's bug bounty program, and no exploitation in the wild has been confirmed. The vulnerabilities affect TeamViewer Full Client, Host, and QuickSupport across Windows, macOS, and Linux platforms. Users are urged to update to version 15.81.5 or newer to mitigate these risks. The vulnerabilities were published on August 26, 2026, and are classified as high severity with CVSS scores of 7.5 and 8.8, respectively.

Key Points: • Two critical vulnerabilities in TeamViewer patched: CVE-2026-16444 and CVE-2026-19042. • CVE-2026-16444 allows file writing and potential code execution by authenticated attackers. • CVE-2026-19042 enables remote code execution via crafted URLs in Linux chat.

Timeline

2026-08-26
CVE-2026-16444 published
TeamViewer disclosed a vulnerability allowing authenticated attackers to write files to unintended locations.
TeamViewer
2026-08-26
CVE-2026-19042 published
TeamViewer announced a command injection vulnerability enabling remote code execution via chat in Linux.
TeamViewer
2026-08-28
TeamViewer releases security updates
TeamViewer released version 15.81.5 to patch the identified vulnerabilities across all platforms.
Heise.De