# TeamViewer patches five vulnerabilities, including flaws that allow code execution through a remote session > TeamViewer bulletin TV-2026-1010 covers five flaws in the Windows, Linux and macOS clients, fixed in version 15.82. What is known, and what Mac users can check. FireAI Security & Research Team (HisnLabs) ยท Published 2026-10-01 Canonical: https://hisnlabs.com/en/news/teamviewer-vulnerabilities-code-execution-remote-session TeamViewer published security bulletin TV-2026-1010 on 29 September 2026 for five vulnerabilities in its Full Client and Host on Windows, Linux and macOS, and Cyber Security News reported on them on 1 October 2026 [[1]](https://cybersecuritynews.com/teamviewer-vulnerabilities/) [[2]](https://www.teamviewer.com/en/resources/trust-center/security-bulletins/tv-2026-1010/). Two of them can lead to code execution, one through a crafted session file and one through a bypass of permission settings. TeamViewer states that it is not aware of public disclosure or active exploitation [[2]](https://www.teamviewer.com/en/resources/trust-center/security-bulletins/tv-2026-1010/). ## Background TeamViewer is remote access software: a person or a support technician connects to a computer and sees or controls its screen. The client also keeps its own local services and can record and replay sessions. A flaw in such a program matters because the program usually runs with wide permissions and is installed on machines that handle work and personal accounts alike. ## Findings The bulletin lists five CVE identifiers. CVE-2026-19743, an improper path validation in the local IPC service, is scored 7.8. CVE-2026-92368, a heap-based buffer overflow in session playback, is scored 7.8 and listed with remote code execution as its impact. CVE-2026-92369, a race condition in the Windows installer rollback, is scored 7.3. CVE-2026-92371, an improper path validation in Cloud Session Recording, is scored 7.0 [[2]](https://www.teamviewer.com/en/resources/trust-center/security-bulletins/tv-2026-1010/). The most severe, CVE-2026-92370, is scored 8.8. The bulletin describes it as an improper access control vulnerability that allows an authenticated remote attacker to bypass user-configured permission settings [[2]](https://www.teamviewer.com/en/resources/trust-center/security-bulletins/tv-2026-1010/). Cyber Security News adds that this could potentially enable remote code execution, and that the playback flaw is triggered when a malicious session file with the .tvs extension is opened [[1]](https://cybersecuritynews.com/teamviewer-vulnerabilities/). The fix is version 15.82 for all platforms, together with updates for legacy maintenance releases. Cyber Security News lists the affected versions as those before 15.82 and the legacy lines 15.64, 14.7 and 13.2 [[1]](https://cybersecuritynews.com/teamviewer-vulnerabilities/) [[2]](https://www.teamviewer.com/en/resources/trust-center/security-bulletins/tv-2026-1010/). The bulletin gives the priority as Important and the top CVSS score as 8.8, rated High; the word Critical in the article's headline is the outlet's own wording [[1]](https://cybersecuritynews.com/teamviewer-vulnerabilities/) [[2]](https://www.teamviewer.com/en/resources/trust-center/security-bulletins/tv-2026-1010/). > FireAI, the on-device firewall for macOS developed by HisnLabs, lists apps with known security flaws once threat data is turned on, so an outdated remote access client can be spotted. A 17-day trial is available. [Download FireAI for Mac](https://hisnlabs.com/en/download) ## Implications for Mac users The bulletin names macOS among the affected platforms, so a Mac with TeamViewer installed below version 15.82 is within scope [[2]](https://www.teamviewer.com/en/resources/trust-center/security-bulletins/tv-2026-1010/). Exploiting the playback flaw requires the target to open a session file, and the access-control flaw requires an authenticated remote attacker, so neither is described as working against a client that has never been used [[1]](https://cybersecuritynews.com/teamviewer-vulnerabilities/). Remote support tools are often installed once, for a single help session, and then left in place; such an installation is the one that stays unpatched. ## Recommendations 1. Update TeamViewer to version 15.82 or the latest available release, as the bulletin advises [[2]](https://www.teamviewer.com/en/resources/trust-center/security-bulletins/tv-2026-1010/). 2. Uninstall the client if it was installed for a single support session and is no longer used. 3. Do not open .tvs session files that arrive from an unknown sender, since the playback flaw is triggered by such a file [[1]](https://cybersecuritynews.com/teamviewer-vulnerabilities/). 4. Review the permission settings configured in TeamViewer, because the most severe flaw concerns bypassing them [[2]](https://www.teamviewer.com/en/resources/trust-center/security-bulletins/tv-2026-1010/). ## Relevance to FireAI FireAI does not patch TeamViewer, inspect session files or detect an exploit of these flaws. With threat data turned on, [Apps that need an update](https://hisnlabs.com/en/docs/apps-that-need-an-update) checks the versions of apps it has seen connecting against public vulnerability databases and lists those with known flaws, provided the app is one it can name in the database; whether that covers these five CVEs depends on when the databases list them. [Rules](https://hisnlabs.com/en/docs/per-app-rules) and [blocking an app](https://hisnlabs.com/en/docs/block-an-app-or-a-company) let a user stop TeamViewer from reaching the internet while it is not needed, and [Activity](https://hisnlabs.com/en/docs/activity-and-connection-history) shows when it connects. > A remote access client that is installed but unused still has a network path. FireAI can block that app from the internet until it is needed. Try it free for 17 days. [Download FireAI for Mac](https://hisnlabs.com/en/download) ## Limitations Both sources were read through a page summary, and the exact affected-version ranges and the per-CVE impact labels were taken from them without access to the full bulletin text. The article and the bulletin differ in tone: the article calls the flaws critical, while the bulletin rates the highest score as High. Neither source describes exploitation steps in detail, a proof of concept or a public report of attacks. Try [FireAI, by HisnLabs](https://hisnlabs.com/en/download) free for 17 days. ## Sources - [Cyber Security News, 1 October 2026: Critical TeamViewer vulnerabilities enable code execution attacks via remote session](https://cybersecuritynews.com/teamviewer-vulnerabilities/) - [TeamViewer Trust Center, 29 September 2026: Security bulletin TV-2026-1010](https://www.teamviewer.com/en/resources/trust-center/security-bulletins/tv-2026-1010/)