Summary
- Bulletin TV-2026-1010 covers five CVEs with CVSS scores of up to 8.8.
- The flaws include path traversal, buffer overflow, access-control, and privilege-escalation weaknesses.
- TeamViewer says it is not aware of public disclosure or active exploitation of the vulnerabilities.
TeamViewer has released security updates for five high-severity vulnerabilities affecting its clients and related services, including weaknesses that can enable remote code execution and local privilege escalation.
TeamViewer published bulletin TV-2026-1010 on 29 September, assigning CVSS scores of up to 8.8 to the set of flaws. The affected product families include TeamViewer Remote, Tensor, and ONE.
CVE-2026-19743 is a path-traversal weakness in the local IPC service that can allow a low-privileged authenticated user to perform arbitrary file writes with elevated privileges. TeamViewer says successful exploitation can lead to local privilege escalation.
CVE-2026-92368 affects the processing of session-recording files on Linux and macOS. A heap-based buffer overflow can be triggered when a user opens a specially crafted recording, potentially allowing arbitrary code execution with the privileges of the current user.
CVE-2026-92369 is a Windows installer race condition that can provide local privilege escalation during rollback, while CVE-2026-92371 involves improper link resolution in Linux cloud-session recording functionality.
The highest-scoring flaw, CVE-2026-92370, is an access-control weakness affecting remote sessions. TeamViewer says an authenticated remote attacker can manipulate access-control parameters during session establishment and perform actions that the victim’s configuration had explicitly denied, potentially leading to remote code execution.
The differences between the five vulnerabilities are important. They do not represent five equivalent unauthenticated remote compromises: several require local access, a crafted file, an authenticated session, user interaction, or successful exploitation of a race condition.
TeamViewer says the vulnerabilities have been resolved in version 15.82 and corresponding supported maintenance and legacy releases. The company recommends updating to the latest available version.
It also states that it is not aware of public disclosure or active exploitation in the wild. The immediate issue is therefore patch exposure rather than evidence of an active compromise campaign.
The product category nevertheless warrants close attention because remote-access software often occupies a privileged position inside enterprise support environments. These tools are deliberately trusted across endpoint fleets, used by administrators, and permitted through controls that would otherwise restrict remote access.
The same characteristics have made legitimate remote-management tools attractive after attackers obtain credentials. Vulnerabilities provide a different route into the same administrative ecosystem, particularly where older clients persist outside the normal application-management process.
Distributed ownership can make that upgrade problem harder. TeamViewer may be deployed internally, installed on unattended systems, or managed by an outsourced IT provider, so identifying every affected client can require coordination across several operating teams or suppliers.
The bulletin therefore sits at the intersection of software vulnerability management and third-party operational dependency. TeamViewer has not reported active exploitation, but systems that provide remote administrative access carry a different consequence profile from ordinary desktop applications if a security weakness is successfully used.
The five issues are fixed in current releases, leaving inventory and upgrade coverage as the main immediate questions for organisations running older clients or hosts.





