TeamViewer's update fixes the thing where a session ignores what you allowed
If somebody has ever helped you with your PC from a distance, there is a decent chance TeamViewer was how they did it. It is also the program tech-support scammers ask people to install. Either way, a lot of home machines have it, often left over from a one-off repair years ago.
TeamViewer published bulletin TV-2026-1010 on 29 September covering five vulnerabilities in the Full Client and Host on Windows, Linux and macOS. The one to care about is CVE-2026-92370, scored 8.8. When you accept an incoming session you choose what the other side may do, and this flaw lets those choices be bypassed while the session is being set up, in the worst case all the way to running code on your machine. The other four, CVE-2026-19743, CVE-2026-92368, CVE-2026-92369 and CVE-2026-92371, are local problems: a path traversal, a heap overflow, a race condition and a path validation mistake, each of which can take an ordinary account up to SYSTEM.
Version 15.82 fixes all five, and TeamViewer has backported patches to older maintenance builds including 15.64.8 and 14.7.48855. The company says it knows of no public exploit code and no attacks using these. That is the good version of this news, and it is the reason to update now rather than after somebody works out the details.
Open TeamViewer, check Help and About, and update if you are below 15.82. If you cannot remember why it is installed, that is an answer in itself: uninstall it. A remote access tool you do not use is a door you are not watching. Tendvane can push TeamViewer and everything else on the PC to current versions through winget in one pass, and its safety check will tell you what remote access software is sitting there.