BoletimSec•August 28, 2026•🇵🇹Translated from Portuguese

TeamViewer Patches High-Severity Flaws Allowing Remote Command Execution and Unauthorized File Writes

TeamViewer has released patches for two high-severity vulnerabilities in its remote access products that could allow attackers to execute arbitrary commands and write files outside intended directories.

The most critical flaw, identified as CVE-2026-19042 and assigned a CVSS score of 8.8, affects TeamViewer Remote, Tensor, and ONE Full Client and Host components on Linux prior to version 15.81.5. Successful exploitation grants command execution with the privileges of the currently logged-in user. To deliver the malicious message, an attacker must already appear in the victim's contact list or obtain explicit permission to send messages from external users.

The second vulnerability, CVE-2026-16444 with a CVSS score of 7.5, results from insufficient validation of file paths. It impacts TeamViewer clients for Windows, macOS, and Linux before version 15.81.5. During an active remote session, files transferred or content sent via the virtual clipboard may contain path traversal sequences, enabling writes outside the expected directory and potential code execution under the affected user's permissions.

Older product lines, including editions supporting Windows 7 and Windows 8 as well as legacy TeamViewer 13 and TeamViewer 14 releases, also received specific security updates. The vendor strongly recommends upgrading to the most recent available version to mitigate the risks.

No evidence of active exploitation of either vulnerability had been observed at the time the security bulletins were published.

Related articles

Security NEXT•Vulnerabilities & Exploits

Cisco Patches 14 Vulnerabilities in NX-OS Software, Four Rated Critical

Cisco Systems has released security updates addressing 14 vulnerabilities in its Cisco NX-OS Software used in network devices. Four of the seven security advisories published on October 7, 2026, are rated Critical, while three are rated Medium. Several critical issues affect the Cisco Nexus 3000 Series and Nexus 9000 Series switches, impacting features such as NGOAM, MPLS OAM, and the NX-API management interface. Seven vulnerabilities received CVSSv3.1 base scores of 9.0 or higher, with multiple flaws enabling remote code execution as root or denial-of-service conditions. Specific CVEs including CVE-2026-76485, CVE-2026-76486, and CVE-2026-76501 stem from input validation failures in the NGOAM feature and may require SRv6 or NV Overlay configurations to be exploitable. The advisories also cover control plane denial-of-service issues, Python sandbox escapes, and endpoint group contract bypasses in ACI mode.

Security NEXT•Vulnerabilities & Exploits

HPE Networking ClearPass Policy Manager Hit by 28 Vulnerabilities Including 10 Rated Critical

Hewlett Packard Enterprise has disclosed 28 vulnerabilities in its HPE Networking ClearPass Policy Manager product and released security updates to address them. The issues span the web management interface, APIs, endpoint agents, and client software components. Ten of the flaws received a Critical severity rating. Notable issues include SQL injection, multiple authentication bypasses, unsafe deserialization leading to remote code execution, and path traversal. No public exploit code or active discussions were observed at the time the advisory was published on October 6, 2026. The company urges customers to apply the available patches promptly.

Hispasec•Vulnerabilities & Exploits

Attackers Exploit Critical Atlassian Data Center Flaw CVE-2026-21589 Hours After PoC Release

Exploitation attempts against CVE-2026-21589 began almost immediately after technical details and a Nuclei template were published. The vulnerability allows unauthenticated arbitrary file read in multiple Atlassian Data Center products and carries a CVSS v4.0 score of 9.3. In environments integrated with Crowd, attackers who obtain crowd.properties can extract plaintext credentials and escalate to administrator privileges via the Crowd API. The flaw stems from improper handling of double-colon sequences in a shared web resource library, enabling path traversal against plugin resource endpoints. Affected products include Bitbucket Data Center, Confluence Data Center, Jira Software Data Center, Jira Service Management Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye. Atlassian urges immediate patching outside normal cycles and recommends WAF rules or Tomcat RewriteValve configurations to block traversal patterns. Organizations should also review access logs for double-decoded URLs containing .., /, \, or :: sequences.

AntiMalware•Vulnerabilities & Exploits

LibreOffice and Apache OpenOffice Flaw Enables Remote Code Execution via Malicious Calc Tables Without Macro Warnings

Researchers have demonstrated an attack against LibreOffice and Apache OpenOffice users that executes arbitrary Java code simply by opening a malicious spreadsheet, without requiring macro permissions or triggering any security prompts. The vulnerability requires Java support to be enabled in the office suite and exploits legitimate features in the Calc component that automatically fetch data from external database sources. When a crafted document is opened, Calc loads a linked database file that references a malicious Java driver, allowing the attacker’s code to run inside the office process. LibreOffice has already patched the issue tracked as CVE-2026-63277 with the release of versions 26.2.5 and 26.8.0 on October 5, while Apache OpenOffice remains vulnerable up to version 4.1.16 under CVE-2026-59265 with a fix expected in 4.1.17. The attack chain works on both Windows and Linux and bypasses macro protections entirely because no user consent dialog appears. Although only a proof-of-concept exploit that launches the calculator has been published so far, the same technique can execute any Java payload. Users of OpenOffice are advised to disable Java or avoid untrusted files until the patch is available.