Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3524 articles · 168905 vulns · 37/41 feeds (7d)
← Back to list
6.3
CVE-2026-2695EXPLOITEDPATCHED
teamviewer · teamviewer dex platform on-premises

Lack of Server-side validation in Instruction Input in TeamViewer DEX Platform (On-Premises)

Description

A remote, authenticated attacker can exploit a vulnerability in TeamViewer DEX to execute arbitrary program code.

Affected Products

VendorProductVersions
teamviewerteamviewer dex platform on-premises0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
teamviewerteamviewercert_advisory90%

References

  • https://www.teamviewer.com/de/resources/trust-center/security-bulletins/tv-2026-1004/

Related News (2 articles)

Tier B
BSI Advisories46d ago
[NEU] [mittel] TeamViewer DEX: Schwachstelle ermöglicht Codeausführung
→ No new info (linked only)
Tier C
VulDB47d ago
CVE-2026-2695 | TeamViewer DEX up to 9.1 input validation
→ No new info (linked only)
CVSS 3.16.3 MEDIUM
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
9.2
CWECWE-20
PublishedMay 13, 2026
Last enriched46d agov3
Tags
remote code execution
Trending Score0
Source articles2
Independent2
Info Completeness10/14
Missing: epss, kev, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (2)

MEDIUMPRE-CVE
Unspecified Vulnerability in TeamViewer Allowing Undisclosed Attack
Trending: 23
MEDIUMCVE-2026-8381EXP
Broken Access Control in TeamViewer DEX Platform (On Premises)

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
May 13, 2026
Discovered by ZDM
May 13, 2026
Updated: severity, affectedVersions, activelyExploited
May 13, 2026
Actively Exploited
May 13, 2026
Exploit Available
May 13, 2026
Patch Available
May 13, 2026
Updated: description, exploitAvailable, tags
May 15, 2026

Version History

v3
Last enriched 46d ago
v3Tier B46d ago

Updated description to include the ability for remote authenticated attackers to execute arbitrary code and marked exploit as available.

descriptionexploitAvailabletags
via BSI Advisories
v2Tier C47d ago

Updated severity to CRITICAL, added affected version 9.1, and marked the vulnerability as actively exploited.

severityaffectedVersionsactivelyExploited
via VulDB
v147d ago

Initial creation