Skip to content

The Edge of the Cyber World See the latest

Apps

TeamViewer Patches 5 Flaws, Worst Hits CVSS 8.8 [2026]

TeamViewer pushed out security bulletin TV-2026-1010 on September 29, 2026, disclosing five vulnerabilities in its Full Client and Host software, the two highest rated at 8.8 and 7.8 on the CVSS 3.1 scale. The company says it has seen no evidence of public exploit code or active exploitation so far, but the flaws sit inside software that effectively functions as a backdoor by design once an attacker gets a foothold, which is exactly why remote-access tools draw this much scrutiny every time a bulletin like this lands.

The timing matters. TeamViewer’s disclosure landed in the same week CISA added a fifth Cisco SD-WAN zero-day and a pair of Citrix NetScaler zero-days to its Known Exploited Vulnerabilities catalog, and days after Oracle shipped a Critical Patch Update covering more than 800 bugs across 17 product families. Patch fatigue is real, and remote-desktop software is the kind of tool IT teams tend to defer updating because it is business-critical and “always just works.” That is precisely the gap attackers look for, the same dynamic seen in this year’s broader cybersecurity threat landscape.

What TeamViewer Actually Disclosed on September 29

The bulletin, published through TeamViewer’s Trust Center, lists five tracked CVEs affecting TeamViewer Remote, TeamViewer Tensor, and TeamViewer ONE. All five were resolved in version 15.82 of the TeamViewer Clients, alongside matching fixes pushed to supported maintenance and legacy branches. TeamViewer rated the most severe issue “Important” with a CVSS score up to 8.8, and urged customers to update “as soon as possible,” according to reporting from BleepingComputer.

None of the five vulnerabilities is described by TeamViewer or by the National Vulnerability Database as an unauthenticated, zero-click remote code execution bug of the kind that triggers a CISA emergency directive. Instead, the set reads like a mix of local privilege escalation, a file-parsing memory bug, and an access-control bypass, the three failure modes that show up most often in software built to bridge two machines across a network boundary. That distinction matters for how organizations should prioritize the fix, and it is worth walking through each bug on its own terms.

The Five CVEs, Ranked by Severity

The headline flaw is CVE-2026-92370, an improper access-control vulnerability in TeamViewer Full Client and Host on Windows, Linux, and macOS, carrying a CVSS score of 8.8. According to the NVD advisory, an authenticated remote attacker already inside a session can bypass permission settings the device owner explicitly configured, performing actions the victim had denied. Tenable’s writeup on the bug echoes that description, and some press coverage has characterized the practical impact as a path toward remote code execution once those denied permissions are bypassed, though the underlying weakness is the access-control failure itself, not a standalone unauthenticated RCE.

CVE-2026-19743 is a local privilege-escalation bug rated 7.8, living in the local inter-process communication service that TeamViewer’s client and host components use to talk to each other on the same machine. The NVD record describes improper path validation that lets a low-privileged, already-authenticated local user write arbitrary files with elevated rights, reaching NT AUTHORITYSYSTEM on Windows or root on Linux and macOS. That is a meaningful bug on shared or multi-user machines, call centers, lab kiosks, shared workstations, but it requires local access first, which narrows the realistic attack surface compared to a network-facing flaw.

CVE-2026-92368, rated 7.8, is a heap-based buffer overflow triggered when TeamViewer’s “Play or convert recorded session” feature processes a malicious .tvs session-recording file. A size mismatch during decompression can cause an out-of-bounds heap write, and a specially crafted recording could execute code with the privileges of whoever opens it, per the GitHub Security Advisory tracking the issue. This is a classic file-format attack vector: convince a support technician or IT admin to open a recording they believe came from a legitimate session, and the payload runs the moment it decompresses.

The remaining two entries, CVE-2026-92369 (7.3) and CVE-2026-92371 (7.0), both rated High but not identical and are grouped in the same bulletin, though TeamViewer’s public advisory text does not spell out their mechanics in the same depth as the other three. Security teams treating TV-2026-1010 as a single “patch now” event rather than parsing each CVE individually will cover all five regardless, since the fix for all of them ships in the same 15.82 build.

CVE CVSS Score Vulnerability Type Attack Prerequisite
CVE-2026-92370 8.8 High Access-control bypass in remote sessions Attacker already in an authenticated session
CVE-2026-19743 7.8 High Local privilege escalation via path validation Local low-privileged user account
CVE-2026-92368 7.8 High Heap buffer overflow in .tvs file parsing Victim opens a malicious recording
CVE-2026-92371 7.0 High Unspecified client/host component flaw Not fully detailed in public bulletin
CVE-2026-92369 Not fully disclosed Session-recording related flaw Not fully detailed in public bulletin

Which Versions Are Affected, and What to Install Instead

TeamViewer’s fix matrix covers more branches than a single “update to the latest version” line suggests, because the company still supports several legacy release trains for customers running older operating systems. The current branch, versions 15.0 up to but not including 15.82, moves to 15.82. A legacy branch built for Windows 7 and 8, spanning 15.64.0 up to 15.64.8, gets its own patched build at 15.64.8. Two older branches covering version 14 on Windows and Linux, running from 14.7.0 up to 14.7.48855, are fixed at 14.7.48855. A still-older Windows branch on the 13.2 line, from 13.2.0 up to 13.2.36230, is fixed at 13.2.36230.

That spread is the real operational headache here. An organization running TeamViewer across a mixed fleet, some newer Windows 11 machines, some aging point-of-sale terminals still on Windows 7, cannot simply push one installer and call it done. IT teams need to inventory exactly which branch each endpoint runs before patching, because grabbing the generic 15.82 installer will not touch a machine still locked to the 13.2 or 14.7 legacy line.

Affected Branch Vulnerable Range Fixed Version Typical Use Case
Current (15.x) 15.0 to before 15.82 15.82 Standard desktop and server installs
Legacy Win 7/8 15.64.0 to before 15.64.8 15.64.8 Older Windows endpoints still in service
Legacy v14 (Win/Linux) 14.7.0 to before 14.7.48855 14.7.48855 Industrial and embedded systems
Legacy v13 (Win) 13.2.0 to before 13.2.36230 13.2.36230 Long-tail legacy deployments

No Confirmed Exploitation, But That Is Not the Same as Safe

TeamViewer’s bulletin and the early press coverage agree on one point: there is no evidence of publicly available exploit code or active exploitation tied to any of the five CVEs as of the disclosure date. That is a meaningfully different risk posture than, say, the Citrix NetScaler or Cisco SD-WAN flaws CISA added to its Known Exploited Vulnerabilities catalog the same week, both of which were already being used in the wild before the public warning went out.

But “no evidence yet” has a short shelf life once a CVSS 8.8 bug with public technical detail is sitting in NVD and GitHub Security Advisories. Security researchers routinely reverse-engineer patches within days of release, a technique known as patch diffing, to reconstruct the exact code change and work backward to a working proof of concept. For a tool installed on hundreds of thousands of help-desk, IT support, and remote-work machines, the incentive to build that proof of concept is high, and the published advisories already describe the vulnerable code paths in enough detail to narrow the search considerably.

Why Remote-Access Software Keeps Showing Up in Security Bulletins

Remote-desktop tools occupy an unusual spot in the security stack: they are designed to grant one machine deep, often privileged control over another, which is the entire point of the product, and also exactly the capability an attacker wants. That dual nature is why TeamViewer, AnyDesk, Splashtop, ConnectWise ScreenConnect, and similar tools have all drawn security research attention over the past several years, independent of whether any individual company has had a worse track record than its peers.

It also explains why ransomware crews and scam operators have repeatedly abused legitimate remote-access software rather than building custom malware from scratch. A tech-support scam that talks a victim into installing TeamViewer, or a ransomware affiliate that finds ConnectWise ScreenConnect already deployed on a compromised network, gets the same level of access a real IT admin would have, without tripping antivirus signatures tuned to detect unfamiliar executables. That abuse pattern is separate from the TV-2026-1010 vulnerabilities themselves, but it is the backdrop against which every TeamViewer security bulletin gets read by defenders.

How This Compares to Earlier Remote-Access Security Incidents

TeamViewer’s own history includes a widely discussed 2016 wave of account-takeover complaints, which the company attributed at the time to credential reuse from unrelated third-party breaches rather than a flaw in its own software, and a 2024 corporate network intrusion tied to the APT29 threat group, which TeamViewer said was confined to its internal IT environment and did not touch the product or customer data. TV-2026-1010 is a different category of event altogether: a vendor-disclosed, coordinated set of product vulnerabilities with CVE identifiers, NVD entries, and a shipped fix, the kind of routine-but-serious bulletin that well-run software vendors issue when their own testing or outside researchers find bugs before attackers do.

That is worth separating clearly because the three categories, account-takeover from reused passwords, a breach of the vendor’s own corporate network, and a flaw in the shipped software, get conflated constantly in headlines and in IT department Slack channels. Only the third category, the one in play this week, requires an actual software patch. The other two call for different fixes entirely: unique passwords with multi-factor authentication for the first, and nothing at all on the customer side for the second, since it was TeamViewer’s internal network, not its product, that was affected.

Competitive Landscape: How Rivals Stack Up on Security Disclosure

TeamViewer is not alone in the remote-access market, and the way competitors handle disclosure varies. AnyDesk, Splashtop, ConnectWise, and Chrome Remote Desktop all occupy adjacent space, serving IT support desks, managed service providers, and consumer users who need occasional access to a second machine. Each has faced its own security scrutiny over the years, and each publishes patches on its own cadence rather than a shared industry calendar, which means IT teams running more than one of these tools cannot rely on a single patch-Tuesday-style schedule to stay current across the board.

Tool Primary Market Disclosure Channel Latest Flagged Issue (TV-2026-1010 Window)
TeamViewer Enterprise IT support, Tensor/ONE suite Trust Center security bulletins 5 CVEs, up to 8.8 CVSS, fixed in 15.82
AnyDesk Cross-platform remote support Vendor advisories, CVE database entries No comparable disclosure in this window per available reporting
Splashtop SMB and enterprise remote access Vendor security pages No comparable disclosure in this window per available reporting
ConnectWise ScreenConnect MSP and managed IT Vendor advisories, CISA KEV history No comparable disclosure in this window per available reporting
Chrome Remote Desktop Consumer and lightweight business use Google security bulletins No comparable disclosure in this window per available reporting

The absence of a comparable entry for the other four vendors in this specific week should not be read as those products being inherently more secure. It reflects what turned up in current public reporting around the TV-2026-1010 disclosure window, and ConnectWise ScreenConnect in particular has a documented history of being targeted by CISA’s Known Exploited Vulnerabilities catalog in past cycles. The fairer takeaway is that every remote-access vendor in this category eventually ships a bulletin like this one, because the software’s job, bridging trust boundaries between machines, makes it a permanent target for security research regardless of how carefully any individual company builds it.

What IT Teams Should Actually Do This Week

The practical response breaks into three tiers. First, inventory: identify every endpoint running TeamViewer Full Client or Host, and tag which version branch each one is on, since the 15.x, 15.64.x, 14.7.x, and 13.2.x lines all need different installers. Second, patch: push 15.82 or the matching legacy fix to every machine identified, prioritizing internet-facing support desks and any system where TeamViewer sessions cross organizational boundaries, since CVE-2026-92370’s access-control bypass is specifically a remote-session issue. Third, harden: disable or restrict the “Play or convert recorded session” feature where business workflows allow it, since that is the specific feature path tied to CVE-2026-92368, and train support staff not to open session recordings from unverified sources.

Organizations running TeamViewer Tensor in a managed enterprise rollout have an advantage here: centralized policy push means a single admin action can force the update across the fleet, rather than relying on individual end users to click through an update prompt. Shops still running the free or single-license version of TeamViewer, common in small businesses and home-office setups, carry more exposure simply because there is no central IT function forcing the update, and prior tech-support-scam abuse of TeamViewer specifically targeted exactly that less-managed user base.

Market and Industry Context: A Crowded Patch Week

TV-2026-1010 did not land in isolation. The same week saw Microsoft’s September Patch Tuesday address two actively exploited zero-days and 113 critical vulnerabilities, Oracle’s Critical Patch Update cover more than 800 flaws across 17 product families, ISC ship BIND 9 fixes for 14 vulnerabilities including seven rated high severity, and CISA add Citrix NetScaler and Cisco Catalyst SD-WAN Manager bugs to its Known Exploited Vulnerabilities catalog after confirming in-the-wild attacks. It followed close behind other enterprise-software scrambles this cycle, including the F5 BIG-IP APM zero-day rated CVSS 9.8, the SharePoint CVE-2026-65660 CISA deadline, and the WSO2 CVSS 10 API flaw that was exploited less than two weeks before it landed on the KEV list. Security teams working through that backlog have a limited number of patch windows, and remote-access software, despite running on effectively every support desk in the world, often loses the prioritization fight against vendor-labeled “critical, actively exploited” tags elsewhere on the list.

That prioritization problem is arguably the more interesting story here than any single CVE. TeamViewer rated its own worst bug “Important” rather than “Critical,” and confirmed no active exploitation, two factors that will push TV-2026-1010 lower on most triage lists this cycle. But the installed base for remote-access software is enormous and largely invisible to central IT, since so much of it gets installed ad hoc by individual employees or support technicians rather than through managed software deployment. A bug that is easy to deprioritize on paper can still represent the single largest patch gap in an organization’s actual environment, simply because nobody tracked where all the installs live.

What Happens Next: Five Predictions

Expect independent researchers to publish technical write-ups and likely proof-of-concept code for at least CVE-2026-92370 and CVE-2026-92368 within the next two to four weeks, following the standard patch-diffing timeline seen after most high-severity remote-access disclosures. Expect CISA to monitor TV-2026-1010 for possible addition to its Known Exploited Vulnerabilities catalog if any credible exploitation signal emerges, though that is not guaranteed given the access prerequisites involved in several of the five bugs. Expect TeamViewer to publish a follow-up advisory or FAQ addressing the still-vague technical detail around CVE-2026-92369 and CVE-2026-92371, since security researchers and vulnerability database maintainers typically push vendors for fuller disclosure once initial coverage lands. Expect managed service providers and IT asset management vendors to add TeamViewer version-branch detection to their patch compliance dashboards, given how fragmented the fix matrix is across four separate release trains. And expect at least one of TeamViewer’s direct competitors, AnyDesk, Splashtop, or ConnectWise, to face its own disclosure cycle before the end of 2026, consistent with the pattern across this entire product category over the past several years.

The Bigger Picture for Remote Work and IT Support

Remote-access software became permanent infrastructure during the shift to hybrid and remote work, and it has not gotten any less central since. Help desks, managed service providers, embedded-systems technicians, and even consumer tech support all lean on tools like TeamViewer daily, which means a CVSS 8.8 bug in that category, even one with no confirmed in-the-wild exploitation, deserves the same patch-window priority as a critical flaw in a more visible piece of infrastructure. The fact that TeamViewer caught and disclosed these five issues through its own process, rather than in response to an active breach, is the system working the way it is supposed to. Whether the long tail of unmanaged, home-office, and small-business installs actually gets the 15.82 update before a working exploit surfaces is the part nobody can fully verify from the outside.

Frequently Asked Questions

What is TV-2026-1010?

TV-2026-1010 is the security bulletin TeamViewer published on September 29, 2026, disclosing five vulnerabilities, tracked as CVE-2026-19743, CVE-2026-92368, CVE-2026-92369, CVE-2026-92370, and CVE-2026-92371, across its Full Client and Host software for TeamViewer Remote, Tensor, and ONE.

What is the most severe TeamViewer vulnerability in this bulletin?

CVE-2026-92370 carries the highest CVSS score at 8.8. It is an improper access-control flaw that lets an authenticated remote attacker inside an active session bypass permission restrictions the device owner had configured.

How do I update TeamViewer to fix these vulnerabilities?

Update to TeamViewer Clients version 15.82 if running the current branch. Legacy users on the Windows 7/8 branch need 15.64.8, legacy version-14 Windows or Linux users need 14.7.48855, and legacy version-13 Windows users need 13.2.36230. Check your exact build number before updating, since the generic 15.82 installer does not apply to older legacy branches.

Is there evidence these TeamViewer vulnerabilities have been exploited?

TeamViewer and early security reporting indicate no evidence of publicly available exploit code or active exploitation at the time of disclosure. That status can change quickly once detailed technical advisories are public, so patching promptly is still recommended.

What is CVE-2026-92368 and how is it triggered?

CVE-2026-92368 is a heap-based buffer overflow in how TeamViewer processes .tvs session-recording files. A specially crafted recording opened through the “Play or convert recorded session” feature can trigger an out-of-bounds heap write, potentially executing code with the privileges of the user who opened it.

Does this affect TeamViewer on Mac and Linux, or only Windows?

The access-control and local privilege-escalation issues, CVE-2026-92370 and CVE-2026-19743, affect Windows, Linux, and macOS. The heap overflow in session-recording handling, CVE-2026-92368, is specifically flagged for Linux and macOS builds in the GitHub Security Advisory tracking that issue.

How does this compare to past TeamViewer security incidents?

This is a vendor-disclosed product vulnerability bulletin with a shipped fix, distinct from the 2016 account-takeover complaints TeamViewer attributed to reused passwords from unrelated breaches, and distinct from the 2024 corporate network intrusion the company said was confined to its internal IT systems rather than its product.

Should small businesses without dedicated IT staff worry about this?

Yes, arguably more than large enterprises. Organizations without centralized patch management are the most likely to still be running an unpatched version weeks or months from now, since there is no IT policy forcing the 15.82 update across every installed copy.

Related Coverage

Source: Tech Insider