CVE-2026-65767

8.8

Microsoft · Microsoft Teams for Android

A cross-site scripting (XSS) vulnerability in Microsoft Teams for Android allows an authenticated attacker to perform spoofing attacks over a network.

Executive summary

An authenticated attacker can exploit a cross-site scripting vulnerability in Microsoft Teams for Android to facilitate spoofing attacks, posing a significant risk to user data integrity.

Vulnerability

This vulnerability involves improper neutralization of input during web page generation, classified as CWE-79. The vulnerability requires the attacker to have authenticated access (PR:L) to the application environment.

Business impact

The vulnerability carries a CVSS score of 8.8, indicating a high severity risk. Successful exploitation could allow unauthorized actors to spoof content, potentially leading to phishing, session hijacking, or the unauthorized disclosure of sensitive internal communications within the Teams environment.

Remediation

Immediate Action: Update the Microsoft Teams for Android application to version 1.0.76.202611302 or later as provided by the vendor.

Proactive Monitoring: Monitor application access logs for unusual patterns or unexpected content injection attempts originating from authenticated sessions.

Compensating Controls: Ensure that mobile device management (MDM) policies are strictly enforced to prevent the use of outdated, vulnerable application versions.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the high CVSS score, organizations should prioritize the deployment of the vendor-supplied update across all managed Android devices. Failure to patch may expose users to targeted spoofing campaigns that could compromise confidential business information.

More Microsoft CVEs