Security bulletins
| Bulletin ID | Date Published | Assigned CVE | Titre | CVSS | Priorité | Affected Products | Last Update |
|---|---|---|---|---|---|---|---|
| TV-2026-1009 | 26 août 2026 | CVE-2026-19042 | Command Injection in TeamViewer Clients for Linux through Chat Link Handling | 8.8 (High) | élevé |
|
26 août 2026 |
| TV-2026-1008 | 26 août 2026 | CVE-2026-16444 | Improper Validation of File Paths in TeamViewer Desktop Clients | 7.5 (High) | élevé |
|
26 août 2026 |
| TV-2026-1007 | 29 juil. 2026 | CVE-2026-12703 | Bypass of 2FA for Connections via Unattended Access in TeamViewer for macOS | 8.0 (High) | élevé |
|
29 juil. 2026 |
| TV-2026-1006 | 29 juin 2026 | Vulnerability in TeamViewer out-of-session chat | Informative |
|
29 juin 2026 | ||
| TV-2026-1005 | 22 mai 2026 | CVE-2026-8381 | Broken Access Control in TeamViewer DEX Platform (On‑Premises) | 5.4 (Medium) | moyenne |
|
22 mai 2026 |
| TV-2026-1004 | 13 mai 2026 | CVE-2026-2695 | Lack of Server-side validation in Instruction Input in TeamViewer DEX Platform (On-Premises) | 6.3 (Medium) | moyenne |
|
13 mai 2026 |
| TV-2026-1003 | 5 févr. 2026 | CVE-2026-23572 | Access control vulnerability in TeamViewer Full and Host clients | 7.2 (High) | élevé |
|
5 févr. 2026 |
| TV-2026-1002 | 29 janv. 2026 | CVE-2026-23563, CVE-2026-23571 | Improper Input and Privilege Handling for Authenticated Users in TeamViewer DEX (former 1E DEX) | Up to 6.8 (Medium) | moyenne |
|
29 janv. 2026 |
| TV-2026-1001 | 29 janv. 2026 | CVE-2026-23564, CVE-2026-23565, CVE-2026-23566, CVE-2026-23567, CVE-2026-23568, CVE-2026-23569, CVE-2026-23570 | Vulnerabilities in TeamViewer DEX Client (former 1E Client) – Content Distribution Service (NomadBranch.exe) | Up to 6.5 (Medium) | moyenne |
|
29 janv. 2026 |
| TV-2025-1006 | 11 déc. 2025 | CVE-2025-64986, CVE-2025-64987, CVE-2025-64988, CVE-2025-64989, CVE-2025-64990, CVE-2025-64991, CVE-2025-64992, CVE-2025-64993, CVE-2025-64994, CVE-2025-64995 | Command Injection and Privilege Escalation vulnerabilities in Teamviewer DEX (former 1E DEX) Instructions | Up to 7.2 (High) | moyenne |
|
11 déc. 2025 |
| TV-2025-1005 | 11 déc. 2025 | CVE-2025-12687, CVE-2025-44016, CVE-2025-46266 | Improper input validation in TeamViewer DEX Client (former 1E Client) – Content Distribution Service (NomadBranch.exe) | Up to 8.8 (High) | élevé |
|
11 déc. 2025 |
| TV-2025-1004 | 30 sept. 2025 | CVE-2025-41421 | Privilege Escalation via Symbolic Link Spoofing in TeamViewer Client | 4.7 (Medium) | moyenne |
|
1 oct. 2025 |
| TV-2025-1003 | 26 août 2025 | CVE-2025-44002 | Arbitrary File Creation via Symbolic Link Leading to Denial-of-Service | 6.1 (Medium) | moyenne |
|
26 août 2025 |
| TV-2025-1002 | 24 juin 2025 | CVE-2025-36537 | Incorrect Permission Assignment for Critical Resource in TeamViewer Remote Management | 7.0 (High) | élevé |
|
24 juin 2025 |
| 1E-2025-2001 | 12 mars 2025 | CVE-2025-1683 | Symbolic link exploit in 1E client | 7.8 (High) | élevé |
|
13 mars 2025 |
| TV-2025-1001 | 28 janv. 2025 | CVE-2025-0065 | Improper Neutralization of Argument Delimiters in TeamViewer Clients | 7.8 (High) | élevé |
|
28 janv. 2025 |
| TV-2024-1008 | 11 déc. 2024 | CVE-2024-12363 | Insufficient permissions in the “TeamViewer Patch & Asset Management” component. | 7.1 (High) | élevé |
|
11 déc. 2024 |
| TV-2024-1006 | 25 sept. 2024 | CVE-2024-7479, CVE-2024-7481 | Improper signature verification of driver installation in TeamViewer Remote clients | 8.8 (High) | élevé |
|
25 sept. 2024 |
| TV-2024-1007 | 27 août 2024 | CVE-2024-6053 | Improper access control in the clipboard synchronization feature in TeamViewer Remote full client and TeamViewer Meeting | 4.3 (Medium) | moyenne |
|
27 août 2024 |
| 1E-2024-2001 | 31 juil. 2024 | CVE-2024-7211 | 1E platform URL redirection | 4.7 (Medium) | moyenne |
|
2 août 2024 |
| TV-2024-1005 | 27 juin 2024 | TeamViewer IT security update | Informative |
|
4 juil. 2024 | ||
| TV-2024-1004 | 28 mai 2024 | CVE-2024-2451 | Improper fingerprint validation in TeamViewer client prior Version 15.54 | 6.4 (medium) | moyenne |
|
28 mai 2024 |
| TV-2024-1003 | 10 avr. 2024 | CVE-2024-3094 | XZ Utils backdoor – TeamViewer services are not affected | Informative | 10 avr. 2024 | ||
| TV-2024-1002 | 26 mars 2024 | CVE-2024-1933 | Improper symlink resolution in TeamViewer Remote client for macOS | 7.1 (high) | moyenne |
|
26 mars 2024 |
| TV-2024-1001 | 27 févr. 2024 | CVE-2024-0819 | Incomplete protection of personal password settings | 7.3 (high) | élevé |
|
27 févr. 2024 |
| 1E-2023-2003 | 6 nov. 2023 | CVE-2023-45161 | Improper input validation in 1E network product pack | 9.9 (Critical) | Critical |
|
21 nov. 2023 |
| 1E-2023-2005 | 6 nov. 2023 | CVE-2023-45163 | Improper input validation in 1E platform network product pack | 9.9 (Critical) | Critical |
|
21 nov. 2023 |
| 1E-2023-2006 | 6 nov. 2023 | CVE-2023-5964 | Improper Input validation in the end-user interaction product pack available on the 1E exchange | 9.9 (Critical) | Critical |
|
21 nov. 2023 |
| TV-2023-1003 | 20 oct. 2023 | Libwebp vulnerabilities CVE-2023-4863 and CVE-2023-41064 | élevé |
|
20 oct. 2023 | ||
| 1E-2023-2004 | 13 oct. 2023 | CVE-2023-45162 | Improper neutralization of special elements in 1E platform | 9.9 (Critical) | Critical |
|
19 oct. 2023 |
| TV-2023-1002 | 11 oct. 2023 | CVE-2023-38545 | Hotfix for curl and libcurl vulnerability | élevé |
|
11 oct. 2023 | |
| 1E-2023-2001 | 5 oct. 2023 | CVE-2023-45159 | Improper link resolution in 1E client | 8.4 (High) | élevé |
|
19 oct. 2023 |
| 1E-2023-2002 | 5 oct. 2023 | CVE-2023-45160 | Insecure file handling in 1E client for windows | 8.8 (High) | élevé |
|
2 nov. 2023 |
| TV-2023-1001 | 14 juin 2023 | CVE-2023-0837 | Incomplete protection of local device settings | 6.6 (medium) | moyenne |
|
14 juin 2023 |
| TV-2022-1001 | 14 juin 2023 | CVE-2022-23242 | TeamViewer Linux – Deletion command not properly executed after process crash | 6.3 (medium) | moyenne |
|
14 juin 2023 |
| TV-2022-1002 | 22 mars 2022 | CVE-2022-0778 | Updates for OpenSSL vulnerabilities | moyenne |
|
10 janv. 2024 | |
| TV-2021-1002 | 13 déc. 2021 | Server-side hotfix for log4J issue | faible |
|
29 déc. 2021 | ||
| TV-2021-1001 | 19 oct. 2021 | Welcome to the TeamViewer Security Bulletins | Informative | 24 oct. 2023 | |||
| 1E-2020-2001 | 29 déc. 2020 | CVE-2020-27645 | Unquoted search path in 1E client | 8.8 (High) | élevé |
|
21 nov. 2024 |
| 1E-2020-2002 | 29 déc. 2020 | CVE-2020-27644 | 1E client enables privilege escalation | 8.8 (High) | élevé |
|
29 déc. 2020 |
| 1E-2020-2003 | 29 déc. 2020 | CVE-2020-27643 | Improper link resolution in 1E client | 6.5 (Medium) | moyenne |
|
29 déc. 2020 |
| 1E-2020-2004 | 29 déc. 2020 | CVE-2020-16268 | Privilege escalation in 1E client | 8.8 (High) | élevé |
|
29 déc. 2020 |
Security bulletin priority rating
-
Critical • Red
A critical priority is assigned to a problem that touches a core function of TeamViewer’s software or services, and that could have a critical impact on your security posture (such as a RCE vulnerability “in the wild”). We recommend following our communication closely and implementing all advised measures. This will likely include an immediate update of the TeamViewer client.
-
Important • Orange
An important priority is assigned to a problem of TeamViewer’s software or services that could significantly impair your security posture (such as a privilege escalation vulnerability easy to reproduce). We recommend implementing all advised measures. This will likely include an immediate update of the TeamViewer client.
-
Moderate • Yellow
A moderate priority is assigned to a problem of TeamViewer’s software or services that could impair your local security posture only under specific circumstances. We recommend implementing all advised measures. This will likely include an update of the TeamViewer client at the earliest convenience.
-
Low • Green
A low priority is assigned to a problem that is unlikely to be reproduced and requires privileged local access to be exploited. We recommend implementing all advised measures. This will likely include an update of the TeamViewer client during the next update cycle. The low priority category also includes general security-related announcements by TeamViewer.
Hall of Fame
2026
2024
2023
2022
2021
Do you want to report a security issue?
TeamViewer’s security team will investigate every submission in our Vulnerability Disclosure Program (VDP).