TL;DR
TeamViewer disclosed five TeamViewer vulnerabilities on September 29, 2026, in its Full Client and Host for Windows, Linux, and macOS. All five are rated High, and the worst, CVE-2026-92370, scores CVSS 8.8. Version 15.82 fixes them.
- Total: 5 CVEs
- Severity: 5 High
- Actively exploited: None confirmed
- Highest severity: 8.8 (High · CVSSv3) — CVE-2026-92370
- Action: Apply the latest security updates now
Turn Microsoft CVEs into GitHub Issues automatically — no copy-pasting, no duplicates.
Try Team free for 14 daysNotable CVEs
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-92370 | 8.8 | CWE-284 | 15.82, 15.64.8 (Legacy Windows 7 & 8), 14.7.48855 (Windows) (+5) | Not exploited |
| CVE-2026-19743 | 7.8 | CWE-22 | 15.82, 15.64.8 (Legacy Windows 7 & 8), 14.7.48855 (Windows) (+5) | Not exploited |
| CVE-2026-92368 | 7.8 | CWE-122 | 15.82 | Not exploited |
| CVE-2026-92369 | 7.3 | CWE-367 | 15.82, 15.64.8 (Legacy Windows 7 & 8), 14.7.48855 (+1) | Not exploited |
| CVE-2026-92371 | 7 | CWE-59 | 15.82 | Not exploited |
Why These TeamViewer Vulnerabilities Matter
TeamViewer gives remote users full control of a computer. Attackers therefore value any weakness that lets them go beyond the access a user granted. Four of the five flaws also let a low-privileged local user gain SYSTEM or root rights. That turns a foothold from phishing or malware into full control of the machine.
How the Attacks Work
Permission Bypass (CVE-2026-92370, CVSS 8.8)
This flaw affects how a session starts. A remote attacker can change access control settings for restricted features. As a result, the attacker can perform actions the victim explicitly denied, which may lead to remote code execution. Its CVSS rating notes that the attack needs some interaction from the victim.
Local Privilege Escalation
CVE-2026-19743 (CVSS 7.8) sits in the local IPC service. Crafted IPC commands can trick the service into writing files with SYSTEM or root rights. On Windows, CVE-2026-92369 (CVSS 7.3) abuses a race in the installer rollback. Meanwhile, CVE-2026-92371 (CVSS 7.0) hits Cloud Session Recording on Linux.
Malicious Recording Files
CVE-2026-92368 (CVSS 7.8) is a heap overflow in the .tvs session recording parser on Linux and macOS. An attacker must convince a user to open a crafted recording.
Affected Versions and Exploitation Status
Version 15.x releases before 15.82 are affected, with platform differences per flaw. Legacy builds for Windows 7 and 8, 14.7, and 13.2 are also listed. Both the permission bypass and the IPC flaw hit all three desktop platforms. No exploitation or public proof-of-concept has been confirmed.
Patch and Mitigation Steps
Update Full Client and Host to 15.82. Legacy users should install 15.64.8, 14.7.48855, or the fixed 13.2 build for their platform. The TeamViewer security bulletin TV-2026-1010 lists every fixed version. Until you patch, avoid opening .tvs files from unknown sources. Also limit who can log in locally to machines running TeamViewer, since most of these TeamViewer vulnerabilities need local access.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!