CVE-2026-65767: Microsoft Teams for Android and iOS Spoofing Vulnerability

Overview

Severity
High (CVSS 8.8)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Category
Spoofing
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2026-Aug
Released
2026-08-11

Description

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allows an authorized attacker to perform spoofing over a network.

FAQ

According to the CVSS metric, successful exploitation of this vulnerability could lead to loss of confidentiality (C:H)? What does that mean for this vulnerability? Successful exploitation of this vulnerability allows an attacker to impersonate another user and access information based on the victim user's permission levels.

Affected Products (1)

Microsoft Office

  • Microsoft Teams for Android

Security Updates (1)

Acknowledgments

Ofek Levin Enclave with <a href="https://enclave.ai/">Enclave AI</a>

Revision History

  • 2026-08-11: Information published.