TEAMVIEWER has patched five high-severity vulnerabilities across its Full Client and Host applications for Windows, Linux and macOS, with the September 29, 2026 security bulletin TV-2026-1010 rating the issues as Important. The most serious, CVE-2026-92370 (CVSS 8.8), is an improper access control flaw that could let an authenticated remote attacker bypass session permissions and perform restricted actions, potentially leading to remote code execution.
The remaining four CVEs involve local access or specific workflow conditions that could enable privilege escalation or other abuse: CVE-2026-19743 (path traversal, CWE-22; 7.8 CVSS), CVE-2026-92368 (heap-based buffer overflow when opening crafted .tvs recordings; CWE-122; 7.8 CVSS), CVE-2026-92369 (TOCTOU race condition during installer rollback; CWE-367; 7.3), and CVE-2026-92371 (improper link resolution on Linux Cloud Session Recording; CWE-59; 7.0). The bulletin also notes CVE-2026-92370’s impact is distinct from the other flaws, which require more specific conditions to be exploited.
Affected versions primarily include Full Client and Host builds before 15.82, with legacy branches receiving fixes as well: 15.x on Windows, Linux, and macOS updated to 15.82; 15.64 legacy for Windows 7 and 8 (15.64.8); 14.7.48855 across Windows, Linux and macOS; 13.2 series on Windows (13.2.36230), Linux (13.2.153995) and macOS (13.2.153994). Administrators are urged to upgrade to 15.82 or later and verify deployments, with legacy branches updated per platform.
TeamViewer states there has been no public confirmation of exploitation as of 1 October 2026, but warns that the risk persists, particularly for unattended‑access endpoints and privileged IT operations. Defenders are advised to restrict unnecessary unattended access, review remote operators, and monitor for suspicious activity in remote sessions, privileged file operations, and unusual endpoint changes, while preserving logs for investigation.