Vulnerabilities fixed in one bulletin: 5 (Source: TeamViewer security bulletin TV-2026-1010 (reported September 30, 2026))
A remote access tool is a planned opening in a computer's defenses. It exists so someone else can see the screen and take control. That puts two things under pressure: the permission settings that limit what a remote person can do, and the privileged service that runs on the machine. TeamViewer's latest bulletin touches both.
TeamViewer published bulletin TV-2026-1010. It covers five vulnerabilities in its Full Client and Host software. Version 15.82 fixes them. The company knows of no public disclosure of the flaws and no real-world attacks that use them.
What TeamViewer fixed
The bulletin describes five separate flaws. BleepingComputer's coverage adds the CVE numbers, which are the public tracking IDs for each flaw.
BleepingComputer ranks one flaw as the most severe: a bypass of session permissions, tracked as CVE-2026-92370. It affects Windows, Linux and macOS. An attacker who is already authenticated can change access settings while a session is starting. That lets the attacker do things the machine's owner had blocked. It could lead to remote code execution, which means the attacker runs their own commands on the target.
The other four flaws are local. The attacker must already be on the machine, or must trick a user into opening a file. BleepingComputer gives their IDs as CVE-2026-19743, CVE-2026-92368, CVE-2026-92369 and CVE-2026-92371.
How the flaws work
Start with the remote bypass. The bulletin's scoring string marks it as reachable over the network. It needs no privileges and some user interaction. It is the only one of the five scored as network-reachable. The other four are scored as local attacks.
One flaw sits in a local background service. That service runs with the highest privileges on Windows, Linux and macOS. Ordinary programs send it commands. TeamViewer says it did not check file paths properly. A low-privileged user could send crafted commands and write files as SYSTEM on Windows or root on Linux and macOS.
A second flaw hits Linux and macOS. It sits in the code that opens .tvs session recording files. A size mismatch while unpacking a recording can write data past the end of a memory block. An attacker must persuade a user to open a crafted recording with the "Play or convert recorded session…" feature. The attacker's code then runs with that user's rights.
A third flaw affects the Windows installer. When an install or update fails, the installer restores backup files from a temporary folder. Ordinary users can write to that folder. A local attacker who swaps the files at the right moment gets SYSTEM access. TeamViewer says the attack needs precise timing and a rollback during the install or update.
The fifth flaw is another race condition, in Cloud Session Recording on Linux. It could cause privileged file operations in unintended places on the system.
Why local flaws still matter
This is our interpretation, not a finding in the bulletin. Local flaws matter most once an attacker has a foothold, or a user's cooperation. They turn a limited account or a single opened file into much greater control of the machine.
BleepingComputer notes that criminals, including ransomware gangs, often misuse TeamViewer to reach victims' systems. It also recalls two breaches of TeamViewer's own corporate network. The outlet calls this a "rare advisory". None of that shows these five flaws are being used. It does show why a privileged, always-installed remote tool draws attention.
The patching work is a matrix
Updating to 15.82 is the main instruction. The bulletin also lists older branches that received fixes: 15.64, 14.7 and 13.2. It names a 15.64 build for Windows 7 and 8. Which operating systems are covered depends on the flaw.
So the real work is knowing what you run. A company with Windows, Linux and macOS machines, and several client versions, cannot assume one update fixes everything.
Questions to put to your IT team
Ask where TeamViewer is installed, on which operating systems, and at which version. Ask which machines run anything older than 15.82. Ask whether any use the Windows 7 and 8 build.
Ask who may open session recording files. Ask whether staff know not to open recordings from unknown senders. Ask whether users can run installers or updates on managed machines.
Ask whether every installation is still needed. A remote tool that nobody uses is still a door.
The lesson: a tool built to hand over control has two lines to hold. Its permission settings decide what a remote party may do. Its privileged local service decides what a foothold can become. This bulletin has flaws in both. Treat its updates the way you treat the lock on your front door.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: TeamViewer.





