Yesterday TeamViewer published bulletin TV-2026-1010. The writeups landed this morning. It says all users should update Full Client and Host to 15.82, or the latest version available, as soon as possible. The flaw is CVE-2026-92370. TeamViewer’s description: an authenticated remote attacker can bypass the permission settings configured for a session, perform actions those settings explicitly denied, and that may lead to code running on the PC. It applies before 15.82 on Windows, Linux, and macOS. TeamViewer says it is not aware of any public disclosure or active exploitation.
What to do: if TeamViewer is installed, for work or at home, install the update today. Don’t wait for it to show up on its own. If the PC is on a maintenance or legacy build, including the Windows 7 and 8 line, use the fixed build listed on the bulletin rather than assuming 15.82 is the right one. The other issues in the same bulletin are a separate matter. The action is still the update. “Not aware of attacks” is TeamViewer’s sentence, not a promise that nobody will try.
A separate reminder, not a breach. Microsoft’s own page says browser sign-in at login.microsoftonline.com will start blocking scripts that are not from Microsoft in mid-to-late October. A third-party copy of message center post MC1481309, dated September 29, says the change begins in mid-October and should finish by late October. That copy is not the admin center. Extensions or helpdesk tools that inject code into that page may stop working. People can still sign in. If the shop does not use those tools, there is nothing to configure.