CVE-2026-65767
8.8Microsoft · Microsoft Teams for Android
A cross-site scripting (XSS) vulnerability in Microsoft Teams for Android allows an authenticated attacker to perform spoofing attacks over a network.
Executive summary
An authenticated attacker can exploit a cross-site scripting vulnerability in Microsoft Teams for Android to facilitate spoofing attacks, posing a significant risk to user data integrity.
Vulnerability
This vulnerability involves improper neutralization of input during web page generation, classified as CWE-79. The vulnerability requires the attacker to have authenticated access (PR:L) to the application environment.
Business impact
The vulnerability carries a CVSS score of 8.8, indicating a high severity risk. Successful exploitation could allow unauthorized actors to spoof content, potentially leading to phishing, session hijacking, or the unauthorized disclosure of sensitive internal communications within the Teams environment.
Remediation
Immediate Action: Update the Microsoft Teams for Android application to version 1.0.76.202611302 or later as provided by the vendor.
Proactive Monitoring: Monitor application access logs for unusual patterns or unexpected content injection attempts originating from authenticated sessions.
Compensating Controls: Ensure that mobile device management (MDM) policies are strictly enforced to prevent the use of outdated, vulnerable application versions.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the high CVSS score, organizations should prioritize the deployment of the vendor-supplied update across all managed Android devices. Failure to patch may expose users to targeted spoofing campaigns that could compromise confidential business information.