Vulnerabilities (CVE)

Filtered by vendor Microsoft Subscribe
Filtered by product Teams
Total 29 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-65767 1 Microsoft 1 Teams 2026-08-16 N/A 8.8 HIGH
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allows an authorized attacker to perform spoofing over a network.
CVE-2026-65769 1 Microsoft 1 Teams 2026-08-16 N/A 6.5 MEDIUM
Exposure of sensitive information to an unauthorized actor in Microsoft Teams Mobile allows an unauthorized attacker to disclose information over a network.
CVE-2026-65768 1 Microsoft 1 Teams 2026-08-14 N/A 8.8 HIGH
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to execute code over a network.
CVE-2026-65667 1 Microsoft 1 Teams 2026-08-11 N/A 10.0 CRITICAL
Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.
CVE-2024-21374 1 Microsoft 1 Teams 2026-08-10 N/A 5.0 MEDIUM
Microsoft Teams for Android Information Disclosure Vulnerability
CVE-2023-29330 1 Microsoft 1 Teams 2026-08-10 N/A 8.8 HIGH
Microsoft Teams Remote Code Execution Vulnerability
CVE-2023-29328 1 Microsoft 1 Teams 2026-08-10 N/A 8.8 HIGH
Microsoft Teams Remote Code Execution Vulnerability
CVE-2026-62918 1 Microsoft 1 Teams 2026-08-07 N/A 7.5 HIGH
Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-62896 1 Microsoft 1 Teams 2026-08-07 N/A 9.6 CRITICAL
Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network.
CVE-2026-42835 1 Microsoft 1 Teams 2026-07-23 N/A 8.1 HIGH
Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.
CVE-2026-33823 1 Microsoft 1 Teams 2026-06-17 N/A 9.6 CRITICAL
Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a network.
CVE-2026-32185 1 Microsoft 1 Teams 2026-06-17 N/A 5.5 MEDIUM
Files or directories accessible to external parties in Microsoft Teams allows an unauthorized attacker to perform spoofing locally.
CVE-2026-26133 1 Microsoft 10 365 Copilot, Edge, Excel and 7 more 2026-06-17 N/A 7.1 HIGH
AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.
CVE-2026-21535 1 Microsoft 1 Teams 2026-06-17 N/A 8.2 HIGH
Improper access control in Microsoft Teams allows an unauthorized attacker to disclose information over a network.
CVE-2025-53783 1 Microsoft 5 Dynamics 365 Guides, Dynamics 365 Remote Assist, Teams and 2 more 2026-06-17 N/A 7.5 HIGH
Heap-based buffer overflow in Microsoft Teams allows an unauthorized attacker to execute code over a network.
CVE-2025-49737 1 Microsoft 1 Teams 2026-06-17 N/A 7.0 HIGH
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Teams allows an authorized attacker to elevate privileges locally.
CVE-2025-49731 1 Microsoft 1 Teams 2026-06-17 N/A 3.1 LOW
Improper handling of insufficient permissions or privileges in Microsoft Teams allows an authorized attacker to elevate privileges over a network.
CVE-2024-42004 1 Microsoft 1 Teams 2026-06-17 N/A 7.1 HIGH
A library injection vulnerability exists in Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger this vulnerability and then make use of the vulnerable application's permissions.
CVE-2024-41145 1 Microsoft 1 Teams 2026-06-17 N/A 7.1 HIGH
A library injection vulnerability exists in the WebView.app helper app of Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger this vulnerability and then make use of the vulnerable application's permissions.
CVE-2024-41138 1 Microsoft 1 Teams 2026-06-17 N/A 7.1 HIGH
A library injection vulnerability exists in the com.microsoft.teams2.modulehost.app helper app of Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger this vulnerability and then make use of the vulnerable application's permissions.