The Easy Kind of Update

TeamViewer fixed five high-severity flaws on September 29. Nobody is using them, there's no exploit code in public, and there's no deadline. Which is exactly why it's ten minutes this week rather than ten hours later.

On September 29, TeamViewer published a security bulletin and shipped version 15.82. Five flaws, all rated high. No exploit code in public, no sign anybody is using them, no federal deadline, no incident. So this is the boring kind of security news, and the boring kind is the one you can act on at your own pace. Ten minutes this week beats ten hours in a quarter. Where we sit: we used TeamViewer until 2012, and we liked it. We left for a dull reason — we were turning into a managed services company, and we took whichever remote tool bolted onto our ticketing system. We've changed both again since. Three remote tools in fourteen years, and every switch was decided by what it integrated with rather than by the tool itself. Which is roughly how the one on your machines got chosen, too, and why nobody has looked at it since. We're not naming the one we use now, and that's deliberate: anyone who knows which remote tool your IT company uses is one phone call from "hi, it's your IT company, accept the session." The technical part — you can skip this box TeamViewer security bulletin TV-2026-1010, published September 29, 2026, covering five vulnerabilities across TeamViewer Remote, Tensor and ONE, in both the Full Client and the Host, on Windows, Linux and macOS. Releases earlier than 15.82 are the affected ones; 15.82 carries the fixes , with backported patch levels on the supported legacy branches 15.64, 14.7 and 13.2. CVE-2026-92370, improper access control, CVSS 8.8 and the highest-rated of the set: an authenticated remote attacker can bypass user-configured permission settings. CVE-2026-19743, path traversal in the local inter-process communication service, CVSS 7.8: a local low-privileged authenticated user can write arbitrary files with elevated privileges. CVE-2026-92368, heap-based buffer overflow in session recording, CVSS 7.8: a size mismatch when decompressing recorded session data produces out-of-bounds heap writes. CVE-2026-92369, a time-of-check to time-of-use race condition in the Windows installer, CVSS 7.3: a local low-privileged attacker can replace rollback backup files and escalate privileges. CVE-2026-92371, link resolution during privileged file operations in cloud session recording on Linux, CVSS 7.0. TeamViewer states it "is not aware of any public disclosure or active exploitation in the wild," and credits the researchers who reported the issues without naming them. What that actually means Four of the five need somebody already on the machine. They turn a limited account into a powerful one. Real, worth fixing, not a reason to cancel your afternoon. The fifth is the interesting one. When you let somebody connect to your computer, you can set what they're allowed to do — move files, see the screen, take the keyboard. Those settings could be stepped around by a remote attacker who had already got as far as being allowed to connect. Which is worth a second's thought. If you've ever let a vendor connect to a machine on restricted permissions, those restrictions were the entire control. Not a belt-and-braces extra. The whole thing. Which direction the version numbers run. Anything older than 15.82 is affected; 15.82 and newer is fixed. On a legacy branch, that branch's patch level is the fix. Bigger is safer. What to do, and the first part takes two minutes Check the version. Open TeamViewer, go to Help, then About TeamViewer. Below 15.82 and it wants updating. Most installations update themselves, so for many of you the check just confirms it. Then the better question: who is on the account? Every ex-employee, every contractor, every "we set this up for you years ago" vendor login still works until somebody removes it. Remote access software is the one category where a stale account isn't a tidiness problem — it's a working key to the inside of a machine. And check whether it's running on machines nobody meant it to be on. Remote access tools spread quietly. One gets installed to solve a Tuesday problem and is still there three years later with nobody's name against it. If we manage your machines, leave the uninstalling to us — some of what looks like stray remote access software is monitoring you're paying for.