CVE-2018-16550: TeamViewer

Critical severity, CVSS 9.8. EPSS: 3.6% chance of exploitation in the next 30 days.

TeamViewer 10.x through 13.x allows remote attackers to bypass the brute-force authentication protection mechanism by skipping the "Cancel" step, which makes it easier to determine the correct value of the default 4-digit PIN.

Affected products

  • TeamViewer TeamViewer: from 10.0.2551, up to and including 13.2.9356

Published 2018-09-05. Last modified 2026-06-17.