TeamViewer's five patched flaws: one scored remote, four local, none known exploited
TeamViewer's bulletin TV-2026-1010 covers five flaws in its Full Client and Host, fixed in build 15.82.6 on the day of disclosure, 29 September. One is scored as network-reachable, TeamViewer knows of no exploitation, and it offers no workaround.
By Parminder Kumar Sharma · · 15 min read

A client patched in August is still in the affected range
TeamViewer shipped 15.81.5 on 25 August with fixes for two flaws, published the next day as bulletins TV-2026-1008 and TV-2026-1009. Thirty-five days later, on 29 September, it shipped 15.82.6 and published bulletin TV-2026-1010: five more flaws in the Full Client and Host, listed for every build below 15.82. That includes 15.81.5. A fleet that did exactly what TeamViewer asked in August is therefore listed as affected by three of the new flaws on Windows or macOS, and four on Linux. The 35 days and the platform counts are our arithmetic from TeamViewer's dates and the bulletin's per-flaw platform lists.
The vendor's message is short. In the bulletin's words, "TeamViewer strongly recommends that all users update to the latest available version as soon as possible." It also says: "TeamViewer is not aware of any public disclosure or active exploitation in the wild." BleepingComputer reported the bulletin on 30 September and headlined it as a warning to patch "as soon as possible". This briefing is built from the primary records instead: the bulletin, the CVE and NVD entries, CISA's exploited-vulnerabilities catalogue and TeamViewer's release notes.
What that does not establish. It does not establish that anyone has exploited any of the five. TeamViewer says it knows of no exploitation, and none of the five CVEs was in CISA's Known Exploited Vulnerabilities (KEV) catalogue in its 30 September release, which I re-checked at 12:17 BST on 1 October. A listing could appear at any time, so read that as a snapshot. It does not establish how many installations are affected: no source I read gives a figure. It does not say the August update was a mistake; a flaw can only be fixed once it is found. And it says nothing about how long any attacker has known of these flaws, because no source says.
The five flaws, at the level a defender needs
All five are in TeamViewer Full Client and Host. TeamViewer scored all five itself, under CVSS 3.1, and each has a CVE record published on 29 September between 15:39 and 15:42 UTC. The NVD entries read "Deferred" when I looked at 12:17 BST on 1 October and carry only TeamViewer's scores. CISA's coordinator has added a decision-support record (SSVC) to each: exploitation none, automatable no, technical impact total.
The five flaws in bulletin TV-2026-1010. Descriptions are condensed from the bulletin. Scores are TeamViewer's CVSS 3.1 base scores, and the second word is the attack vector in its vector string.
| CVE-2026- | What it is | Platforms | Score |
|---|---|---|---|
| 92370 | Remote session access control bypass: an authenticated remote attacker overrides permissions the user configured during session set-up, possibly reaching code execution. | Windows, macOS, Linux | 8.8, network |
| 19743 | Local privilege escalation: a low-privileged local user sends crafted commands to the local service and writes files as SYSTEM or root. | Windows, macOS, Linux | 7.8, local |
| 92368 | Code execution as the current user if a user opens a crafted session recording file (.tvs) with the play or convert feature. | macOS, Linux | 7.8, local |
| 92369 | Local privilege escalation to SYSTEM through a timing race in the installer rollback. It needs a rollback during an install or update. | Windows | 7.3, local |
| 92371 | Local privilege escalation through a race in path handling in Cloud Session Recording. | Linux | 7.0, local |
Four of the five are local. Three are privilege escalations that need code already running on the machine, and the fourth, CVE-2026-92368, needs a user to open a crafted file. None of the four is scored as reachable over the network. They matter as the second half of a break-in. Our inference, not TeamViewer's: a local escalation flaw matters most on shared machines, terminal servers and any host where an attacker already has a foothold, because it turns a low-privileged account into SYSTEM or root. Two of the five, 92368 and 92371, sit in session recording features (our count). The bulletin does not say that leaving those features unused is a mitigation, and nobody should assume it is.
One is scored as network-reachable, and it is the one the bulletin explains least. CVE-2026-92370 says an "authenticated remote attacker" can override permissions the user configured while a session is being established. The bulletin does not say what authenticated means here. In February, bulletin TV-2026-1003 did say, for a different access control flaw: the attacker had to be authenticated to the session by ID and password, session link or Easy Access. TV-2026-1010 gives no such list, and its vector scores privileges required as none and user interaction as required. Our reading, as inference: exposure depends on how your machines accept incoming connections, so hosts set up for unattended access, and any shared connection passwords, deserve the first look. TeamViewer has not said that.
A vector that disagrees with its own description. For CVE-2026-92368 the bulletin page prints privileges required as low and user interaction as none. The CVE record and the NVD entry carry a different vector, privileges none and user interaction required, which matches the description of a user opening a file. The base score is 7.8 on either vector (our recomputation). Inference: a page error. TeamViewer has not said so.
Where the fixes are, and who found the flaws
The fix landed on the same day as the disclosure. TeamViewer's release notes list build 15.82.6 for Windows, macOS and Linux with a release date of 29 September 2026, the bulletin's issue date: zero days between fix and bulletin, and two days to 1 October (our arithmetic). The bulletin says "version 15.82"; the build in the release notes is 15.82.6, so look for that build or later rather than the shorter number.
Older lines carry their own fixes, and the bulletin's table has 20 rows of product, platform and line, six current and 14 legacy (our count). The fixed builds are 15.64.8 for Windows 7 and 8, 14.7.48855 on all three platforms, and 13.2.36230 on Windows, 13.2.153995 on Linux and 13.2.153994 on macOS. The release notes I could read confirm the Windows and Linux 13.2 and 14.7 builds on 29 September. I did not find release notes for the Windows 15.64.8 build or the macOS 13.2 and 14.7 builds, which the bulletin lists as "Download available". The 15.64 line is the one labelled for Windows 7 and 8, so an estate that still runs those systems has to find that specific build, not 15.82.
The bulletin thanks "the security researchers who responsibly reported these issues" and names no one. The CVE records do. Timo De Clercq and 0x_alibabas (Giuliano Sanfins) are credited for CVE-2026-19743; HeaZzy (Mathys KHALFA) and skav (Antoine RIEUL) for CVE-2026-92368 and CVE-2026-92370; Romain Igounet and Hugo Leclercq for CVE-2026-92369 and CVE-2026-92371. That is three sets of finders for five flaws. HeaZzy and skav were also credited on TV-2026-1009 in August, which says it came through TeamViewer's bug bounty program; the records for these five do not say how they were reported.
The CVE records hint at the timeline, with a caveat. The identifier for CVE-2026-19743 was reserved on 13 August, 47 days before publication, and the other four on 16 September, 13 days before (our arithmetic). A reservation is not a report date and not a fix date, so it does not say how long TeamViewer knew of the flaws or how long they were unfixed.
On scope, the bulletin lists TeamViewer Remote, Tensor and ONE as the products and Full Client and Host as the components. It does not use the word Classic, and it does not mention QuickSupport, Portable, Meeting, the mobile apps or MSI packages. That is a change from August's TV-2026-1008, which listed QuickSupport and Portable. Silence is not clearance. The Windows 15.82.6 notes mention new 64-bit MSI packages for Arm-based Windows devices as a feature, not as a security statement, and the Android release notes of the same day carry no security reference.
Stated, and not stated
What TeamViewer, the CVE and NVD records and CISA put on the record about these five flaws, and what none of them says. Read on 1 October 2026.
| Question | On the record | Not stated |
|---|---|---|
| Exploitation | TeamViewer: not aware of any public disclosure or active exploitation. CISA SSVC, 30 September: exploitation none. No entry in KEV release 2026.09.30. | How TeamViewer would know. Any indicator or detection method. A re-check since 29 September: the bulletin's last update is that day. |
| Severity | Priority Important, the second of four levels. CVSS 7.0 to 8.8, High on every flaw, all scored by TeamViewer. | An NVD score of its own (status Deferred). A Critical rating, the level TeamViewer illustrates with a remote code execution flaw seen in the wild. |
| Fix | 15.82, shipped as 15.82.6 on 29 September, plus fixed legacy builds. The advice is to update to the latest version. | A workaround. TV-2026-1003 and TV-2026-1009 each offered one; this bulletin offers none. |
| Scope | Full Client and Host on Windows, macOS and Linux, under Remote, Tensor and ONE. | QuickSupport, Portable, Meeting, mobile apps and MSI packages. The word Classic. The number of installs. |
| The remote flaw | An authenticated remote attacker; scored network, no privileges, user interaction required. | What authenticated means here, and what the user has to do. |
| Finders and timing | Three sets of finders named in the CVE records. Fix and bulletin on the same day. | Any names in the bulletin. When TeamViewer was told of each flaw. When each was introduced. |
The empty cells are the work. Nothing in the bulletin lets a defender tell whether an unexplained session last month was one of these flaws, and nothing says which settings reduce the risk before the update lands.
Three labels that are not controls
"High severity". It is a CVSS band, 7.0 to 8.9 in the CVSS 3.1 specification, and here TeamViewer assigned it to its own flaws. It says how bad a flaw could be on paper. It does not say whether your machines are reachable or how fast you must move. Labels also drift as they travel. TeamViewer's own priority is Important, the second of the four levels its legend defines: Critical, Important, Moderate, Low. BleepingComputer's headline says "severe". One trade headline on 1 October reads "Critical TeamViewer Vulnerabilities" above an article that itself says high-severity. None of the five scores 9.0, where the CVSS Critical band starts; the top score is 8.8.
"As soon as possible". It has no date. TeamViewer's four earlier 2026 client bulletins said "We recommend updating to the latest available version", or close to it; this one is firmer and no more dated. The only dated rule I found is a UK one. The NCSC's Cyber Essentials Requirements for IT Infrastructure v3.3, April 2026, require software on in-scope devices to be updated "within 14 days" of release where the update addresses vulnerabilities with a CVSS v3 base score of 7 or above. All five score 7.0 or more, and the release date was 29 September. For an organisation certified to Cyber Essentials that runs TeamViewer on an in-scope device, the 14 days end on 13 October 2026, twelve days after this briefing (our arithmetic). The requirement also covers a single update that bundles several issues, if any of them meets the threshold. A date is a control. "As soon as possible" is a sentiment.
"No known exploitation". It is a statement about what the vendor knows, not about what is happening on your hosts. The bulletin gives no indicator to hunt for, and it gives no workaround, so between now and the update there is nothing to do except the update. Inference, not a finding: once fixed builds are public, anyone can compare them with older ones, which is why a fix date starts a clock. And the catalogue is not a TeamViewer-free zone: one earlier flaw, CVE-2019-18988, a remote login bypass, was added to KEV on 3 November 2021 with a due date of 3 May 2022. That is a different flaw, and it says nothing about these five.
A remote access tool is a privileged entry point
Two earlier briefings looked at remote access tools from the attacker's side. One covers Microsoft's account of a ransomware affiliate that used six commercial remote management tools across four ransomware brands. The other covers fake payroll applications that installed legitimate remote support software configured for unattended access. In both, the tool was legitimate and the intruder brought the configuration. TeamViewer is named in neither. This briefing is the other half of the problem: the tool you chose, approved and allow-listed has flaws of its own, and an allow-list says nothing about its version.
A remote access product sits where a firewall rule or an identity provider usually sits. It decides who may reach a machine, and it runs with high privilege to do so. The NCSC's guidance Protect your management interfaces lists remote desktops among them and makes the point that applies here: "Management interfaces are written in software, and like all software, can contain vulnerabilities." The advice that follows is to limit who can reach them and to keep an audit trail of what is done through them. That post dates from 2017 and was last updated in March 2025. It is about administrators' own interfaces and does not mention TeamViewer, so I use it for the principle, not as a statement about this bulletin.
Three things an allow-list of approved remote tools does not do. It does not tell you which version each install runs. It does not find the installs nobody approved: our assumption is that they sit on staff laptops, on forgotten servers and on machines a supplier set up. And it does not tell you who may connect, which is the setting this bulletin's one remote flaw is about.
Method and interest. TeamViewer wrote the bulletin, scored the flaws and sells both the product and the fleet controls recommended for patching. Its update-by-policy article says the policy route applies to Business, Premium, Corporate and Tensor licence holders, and its update article says MSI packaging for updating many Windows clients is available with Corporate and Tensor licences. That is normal for a vendor and does not make the advice wrong, but the best tooling for this problem sits on the paid tiers. Everyone else depends on the client's own auto-update, which TeamViewer says "is set by default to check for updates weekly". TeamViewer's article does not say the default also installs the update, and nothing I read says what share of installs update on their own.
What to do, in the order worth doing
Take this with you
For UK IT teams, before 13 October 2026
- Build the inventory first, including installs nobody approved. Search endpoint management, software inventory and process lists for TeamViewer Full Client and Host on Windows, macOS and Linux, and ask suppliers and managed service providers which of your machines they run it on.
- Record the exact version of every install. Anything below 15.82 is listed as affected, including 15.81.5. Older lines need their own build: 15.64.8, 14.7.48855, 13.2.36230 on Windows, 13.2.153995 on Linux and 13.2.153994 on macOS.
- Update, starting with servers and hosts that accept unattended incoming connections. TeamViewer's release notes name build 15.82.6 as the fix on Windows, macOS and Linux. Set an internal deadline, and if you are certified to Cyber Essentials treat 13 October 2026 as the latest date, not the target.
- Check how each install updates. TeamViewer's knowledge base says auto-update checks weekly by default and that a policy can check for and install new versions and be enforced. Confirm what yours do, whether a policy is applied, and whether your licence includes one.
- Restrict who may connect. Remove old contacts and unused unattended-access passwords, use the access controls and conditional access your licence includes, and switch off incoming access on machines that never need it.
- Review connection logs for the weeks before 29 September at least, looking for sessions nobody can explain: unfamiliar remote IDs, out-of-hours sessions and sessions to hosts that should not accept them. TeamViewer has published no indicators for these flaws, so you are looking for unexplained use, not for a signature.
- Remove TeamViewer from machines that do not need it, and from the approved list if another approved tool does the job. Every install is an entry point you must keep patched.
- Write down what you did: the inventory, the versions found and the dates updated. That is your evidence for a Cyber Essentials assessment and for your next incident review.
The question this leaves
TeamViewer's August release closed two flaws and its September release closed five more. The vendor says nobody is exploiting any of them, and it may be right.
So ask your own team one question. If TeamViewer announced tomorrow that one of these five flaws was being exploited, how long would it take you to list every machine that runs the software, and the version each one is on? If the honest answer is longer than a day, the exposure is not these five flaws. It is that you cannot see the tool.
Key facts
Sources
- PrimarySecurity bulletin TV-2026-1010, issued 29 September 2026, read in full: the five CVEs, descriptions, CVSS scores and vectors, affected versions, the exploitation statement, the fix advice and the acknowledgementsTeamVieweraccessed 2026-10-01
- PrimaryTeamViewer security bulletin index and priority definitions, used for the Important priority, the 2026 bulletin cadence and the definition of the four priority levelsTeamVieweraccessed 2026-10-01
- PrimaryCVE record for CVE-2026-92370, the remote flaw; with the records for CVE-2026-19743, 92368, 92369 and 92371 read in the same way, used for finder credits, publication times, reservation dates, vectors and the CISA-ADP SSVC entriesCVE Programaccessed 2026-10-01
- PrimaryNVD entry for CVE-2026-92370 and the other four, read through the NVD API: status Deferred, only TeamViewer's scores, publication and modification timesNIST National Vulnerability Databaseaccessed 2026-10-01
- PrimaryKnown Exploited Vulnerabilities catalogue, release 2026.09.30 of 16:59 UTC, searched for all five CVEs (none present) and for TeamViewer entries (one, CVE-2019-18988)CISAaccessed 2026-10-01
- PrimaryTeamViewer release notes for Windows 15.82.6, dated 2026-09-29; the macOS, Linux and Windows and Linux 13.2 and 14.7 notes of the same date were read alongside it, and the 15.81.5 notes of 2026-08-25 for the earlier releaseTeamViewer Communityaccessed 2026-10-01
- PrimaryBulletin TV-2026-1003 of 5 February 2026, read for how TeamViewer defined an authenticated attacker for an earlier access control flaw and for its offered mitigationTeamVieweraccessed 2026-10-01
- PrimaryBulletin TV-2026-1008 of 26 August 2026, read for the fix in 15.81.5 and for its affected-product list, which included QuickSupport and PortableTeamVieweraccessed 2026-10-01
- PrimaryBulletin TV-2026-1009 of 26 August 2026, read for the 15.81.5 fix, its temporary mitigation and the credit to the researchers also named on two of this week's CVE recordsTeamVieweraccessed 2026-10-01
- PrimaryKnowledge base article Update TeamViewer (last modified 21 May 2026): auto-update checks weekly by default; MSI packaging for many Windows clients is a Corporate and Tensor featureTeamVieweraccessed 2026-10-01
- PrimaryKnowledge base article Update TeamViewer via policy (last modified 29 May 2026): the two policy settings and the licence tiers they apply toTeamVieweraccessed 2026-10-01
- PrimaryCyber Essentials: Requirements for IT Infrastructure v3.3, April 2026, Security Update Management: updates fixing CVSS v3 base score 7 or above are due within 14 days of releaseNCSCaccessed 2026-10-01
- PrimaryNCSC blog Protect your management interfaces (published 22 March 2017, modified 13 March 2025), used for the principle that remote desktops are management interfaces and software that can contain vulnerabilitiesNCSCaccessed 2026-10-01
- PrimaryCVSS v3.1 specification, qualitative severity scale: High is 7.0 to 8.9 and Critical is 9.0 to 10.0FIRSTaccessed 2026-10-01
- Reported byReport of 30 September 2026 by Sergiu Gatlan, read with a browser tool; used as the pointer to the primary sources and for three wordings this briefing checks against the bulletinBleepingComputeraccessed 2026-10-01
- Reported byReport of 1 October 2026, used only for its headline, which says Critical above an article that says high-severityCyber Security Newsaccessed 2026-10-01


