Junglewise Threat Intelligence

CVE-2026-65767: Microsoft Teams for Android cross-site scripting

CVE-2026-65767 · Severity: high · CVSS 8.8 · Published 2026-08-11

Technologies: Microsoft Teams for Android, Microsoft Teams. Vendors: Microsoft.

Executive brief

Microsoft Teams for Android is a mobile messaging and collaboration application used by millions of enterprise users. An attacker with authorized access to the application could inject malicious code that enables spoofing of messages or identities within Teams conversations, potentially compromising the integrity of communications and enabling social engineering attacks.

Technical details

This vulnerability is a cross-site scripting (XSS) flaw arising from improper input sanitization during web page generation in Teams for Android. An authorized attacker can inject malicious script payloads through application inputs that are rendered without proper neutralization. The attack requires the attacker to have authorized access to Teams and for a target user to view the crafted malicious content. Successful exploitation allows the attacker to perform spoofing attacks, potentially forging message origins or identities. Patches are available from Microsoft.

Affected products

  • Microsoft Teams for Android <UNKNOWN>

Timeline

  • 2026-08-11: disclosed

References

Related threats