CVE-2026-65767: Microsoft Teams for Android Spoofing Vulnerability
Overview
- Severity
- High (CVSS 8.8)
- CVSS Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
- Category
- Spoofing
- Exploit Status
- Not Exploited
- Exploitation Likelihood
- Less Likely
- Patch Tuesday
- 2026-Aug
- Released
- 2026-08-11
- Last Updated
- 2026-08-16
- EPSS Score
- 0.61% (percentile: 47.1%)
Description
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allows an authorized attacker to perform spoofing over a network.
FAQ
According to the CVSS metric, successful exploitation of this vulnerability could lead to loss of confidentiality (C:H)? What does that mean for this vulnerability?
Successful exploitation of this vulnerability allows an attacker to impersonate another user and access information based on the victim user's permission levels.
Affected Products (1)
Microsoft Office
- Microsoft Teams for Android
Security Updates (1)
Acknowledgments
Ofek Levin Enclave with <a href="https://enclave.ai/">Enclave AI</a>
Revision History
- 2026-08-11: Information published.
- 2026-08-16: Corrected build number for the security update. This in an informational change only.