CVE-2026-65767
- EPSS 0.44%
- Veröffentlicht 11.08.2026 17:07:17
- Zuletzt bearbeitet 16.08.2026 18:16:45
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allows an authorized attacker to perform spoofing over a network.
CVE-2026-65769
- EPSS 0.66%
- Veröffentlicht 11.08.2026 17:05:19
- Zuletzt bearbeitet 16.08.2026 17:17:30
Exposure of sensitive information to an unauthorized actor in Microsoft Teams Mobile allows an unauthorized attacker to disclose information over a network.
CVE-2026-65768
- EPSS 0.61%
- Veröffentlicht 11.08.2026 17:03:26
- Zuletzt bearbeitet 14.08.2026 13:27:22
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to execute code over a network.
- EPSS 0.45%
- Veröffentlicht 07.08.2026 00:16:38
- Zuletzt bearbeitet 11.08.2026 04:17:26
Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-62918
- EPSS 0.3%
- Veröffentlicht 07.08.2026 00:16:36
- Zuletzt bearbeitet 07.08.2026 19:01:38
Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-62896
- EPSS 0.39%
- Veröffentlicht 07.08.2026 00:16:36
- Zuletzt bearbeitet 07.08.2026 18:10:54
Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network.
CVE-2026-42835
- EPSS 1.26%
- Veröffentlicht 09.06.2026 17:17:09
- Zuletzt bearbeitet 23.07.2026 08:10:00
Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.
CVE-2026-32185
- EPSS 0.47%
- Veröffentlicht 12.05.2026 16:59:00
- Zuletzt bearbeitet 18.05.2026 13:33:56
Files or directories accessible to external parties in Microsoft Teams allows an unauthorized attacker to perform spoofing locally.
CVE-2026-33823
- EPSS 0.72%
- Veröffentlicht 07.05.2026 20:58:52
- Zuletzt bearbeitet 08.05.2026 19:58:39
Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a network.
CVE-2026-26133
- EPSS 0.43%
- Veröffentlicht 13.03.2026 21:10:13
- Zuletzt bearbeitet 09.04.2026 18:16:57
AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.