PatchDayAlert

CVE

CVE-2026-65767

0field notes · 1digest CVSS 8.8

The verdict

A cross-site scripting (XSS) bug in Microsoft Teams for Android lets an authenticated attacker inject malicious content that can spoof UI elements over the network. The attacker needs to be authorized (think: someone already in your tenant or a guest with Teams access), but from there they can craft messages or content that renders malicious scripts in the victim's Teams client.

Patch urgency · Patch this week


Daily digests