Skip to main content
Defentria

Vulnerabilities

TeamViewer fixes five high-severity vulnerabilities and asks users to update to version 15.82

TeamViewer has released patches for five flaws in its remote access software and recommends updating "as soon as possible". INCIBE has issued it as a high-importance warning. There are no known attacks, but in many SMEs TeamViewer has been installed for years without anyone checking it.

By Defentria editorial teamPublished 3 min read

TeamViewer — Vendor of the affected software (TeamViewer Full Client and Host)

Aerial view of TeamViewer's office building in Göppingen (Germany), in light brick with the logo on the façade, next to the railway tracks
Image: TeamViewer AG on Wikimedia Commons (CC BY-SA 4.0, cropped)

In 30 seconds

  • On 29 September TeamViewer released patches for five high-severity vulnerabilities in TeamViewer Full Client and Host, for Windows, Linux and macOS.
  • The most serious one (CVE-2026-92370, CVSS 8.8) could let an attacker bypass the permissions configured for a remote session and potentially run code on the computer.
  • The fix is in version 15.82; the older 15.64, 14.7 and 13.2 versions have their own updates. INCIBE rates it as high importance.
  • TeamViewer says it is not aware of the flaws having been publicly disclosed or being exploited.

Does this affect me?

It affects you if TeamViewer is installed on any computer in your company, whether the full program or the Host module that the IT provider leaves behind for remote support, and it isn't on version 15.82 or later. It's common for it to be installed on machines nobody remembers. It doesn't affect you if you don't use TeamViewer.

What happened

On 29 September 2026, TeamViewer published security bulletin TV-2026-1010, with updates for five vulnerabilities in TeamViewer Full Client and TeamViewer Host, the programs used to control a computer remotely and provide technical support. They affect Windows, Linux and macOS. In its bulletin, the vendor "strongly recommends that all users update to the latest available version as soon as possible".

The next day, INCIBE (Spain's national cybersecurity institute) issued it as a warning for businesses with high importance (4 out of 5). According to INCIBE, the vulnerabilities, "if exploited, could allow an attacker to escalate privileges or execute arbitrary code".

TeamViewer logo
TeamViewer logo. Source: Wikimedia Commons (public domain)

What we know

  • The most serious is CVE-2026-92370, with a CVSS score of 8.8. According to TeamViewer, an authenticated remote attacker could bypass the permissions the user has configured when a session is established, perform actions the user had explicitly denied and potentially run code on the computer.
  • The other four (CVSS between 7.0 and 7.8) mainly let someone who already has access to the computer with an unprivileged account gain administrator permissions. One of them, on Linux and macOS only, is triggered by opening a tampered session recording file (.tvs).
  • Fixed version: 15.82 or later. For the older versions that still receive maintenance, TeamViewer publishes their own fixes: 15.64.8 (Windows 7 and 8), 14.7.48855, and 13.2.36230 (Windows), 13.2.153995 (Linux) or 13.2.153994 (macOS).
  • No known attacks: TeamViewer states that it is not aware of the flaws having been publicly disclosed or being exploited.

What we don't know yet

  • How many devices are still unpatched. Neither TeamViewer nor INCIBE gives figures.
  • Whether they will start being exploited. There are no known attacks today, but that could change at any time.

Why it matters

A remote access program is, by definition, a door into a computer from the outside. That's why these tools are a frequent target: BleepingComputer notes that remote access software is often abused to deploy malware and in ransomware attacks.

The good news is that this time the patch arrives before the attacks. Updating now costs little; doing it after an attack appears costs much more.

What it means for an SME

TeamViewer is one of the most common remote support tools in small businesses. Often nobody in the company installed it: the IT provider left it on every computer, as TeamViewer Host, so they can connect when there's a problem. In practice that means:

  • it may be installed on computers nobody remembers, including a laptop used for remote work;
  • there are old versions (13, 14 or 15.64 on Windows 7 and 8) still running because nobody has touched them;
  • it isn't always clear who can connect or with what permissions.

You don't need to know about IT to sort this out. You need to ask.

What your company should do this week

  1. Ask your IT provider for an inventory of the computers with TeamViewer (Full Client or Host) and the version on each one.
  2. Update to version 15.82 or later. If any computer uses an old version, check that it has its fix and consider replacing it, especially if it still runs Windows 7 or 8.
  3. Uninstall it where it isn't used. Remote access that nobody needs is a risk with no benefit.
  4. Review who can connect and with which accounts, and remove access for people or providers who no longer work with you. Our guide on former employees' access (in Spanish) explains how.
  5. Remind your team not to accept remote sessions from anyone they don't know and not to open session recordings received from outside.

If you're not sure which remote access programs your company has or who uses them, that's exactly what a cybersecurity audit reviews.

Sources

  1. TeamViewer — security bulletin TV-2026-1010, «Security Update for Multiple Vulnerabilities in TeamViewer Clients and Related Services» (29 September 2026)Primary source
  2. INCIBE — «Múltiples vulnerabilidades en TeamViewer», warning INCIBE-2026-683 (30 September 2026)Primary source
  3. BleepingComputer — «TeamViewer urges users to patch severe flaws “as soon as possible”» (Sergiu Gatlan, 30 September 2026)

Defentria editorial team. The Defentria team selects cybersecurity news from primary sources (CERTs, official bodies and vendors) and explains what it means for a Spanish SME and what to do about it.