TeamViewer has published updated packages that close five security flaws in its remote-support software, including one that falls only just short of a "critical" rating. The most serious is an insufficient access-control weakness in the Host, the Full Client and modules derived from them on Linux, macOS and Windows. According to the vendor, authenticated attackers from the network can abuse it to reach functions they should not be allowed to use, trigger unauthorised actions and even run injected code (CVE-2026-92370, CVSS 8.8, rated "high").

Four further holes were fixed in the same release: a pathname-limiting failure (path traversal) in the desktop clients (CVE-2026-19743, CVSS 7.8), a heap-based buffer overflow when playing back session recordings that leads to remote code execution (CVE-2026-92368, CVSS 7.8), a time-of-check to time-of-use race condition in the Windows installer's rollback mechanism that enables local privilege escalation (CVE-2026-92369, CVSS 7.3), and a local privilege escalation via improper link resolution in cloud session recording (CVE-2026-92371, CVSS 7.0).

TeamViewer advises installing Full Client and Host version 15.82 or newer, which is available for Linux, macOS and Windows. Updates exist for older branches as well: releases 14.7 and 13.2 for all three platforms, and 15.64 for Windows 7 and 8. Because the software is affected on every platform — and tools of this kind hold deep privileges on desktops and servers — the developers are telling administrators not to delay patching. The fixes land only weeks after a late-August round of similarly high-risk flaws in the same product.