← Back

Teams

teams

Vendor: Microsoft • 29 CVEs

CVEs (29)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
1Teams
Aug 16, 2026
Aug 11, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Exposure of sensitive information to an unauthorized actor in Microsoft Teams Mobile allows an unauthorized attacker to disclose information over a network.
1Microsoft
1Teams
Aug 14, 2026
Aug 11, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to execute code over a network.
1Microsoft
1Teams
Aug 16, 2026
Aug 11, 2026
N/A· v4
7.6 HIGH· v3
N/A· v2
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allows an authorized attacker to perform spoofing over a network.
1Microsoft
1Teams
Aug 11, 2026
Aug 7, 2026
N/A· v4
10.0 CRITICAL· v3
N/A· v2
Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.
1Microsoft
1Teams
Aug 7, 2026
Aug 7, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing over a network.
1Microsoft
1Teams
Aug 7, 2026
Aug 7, 2026
N/A· v4
9.6 CRITICAL· v3
N/A· v2
Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network.
1Microsoft
1Teams
Jun 17, 2026
Jun 9, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.
1Microsoft
1Teams
Jun 17, 2026
May 12, 2026
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Files or directories accessible to external parties in Microsoft Teams allows an unauthorized attacker to perform spoofing locally.
1Microsoft
1Teams
Jun 17, 2026
May 7, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a network.
1Microsoft
10365 Copilot
EdgeExcel+7 more
Jun 17, 2026
Mar 16, 2026
N/A· v4
7.1 HIGH· v3
N/A· v2
AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.
1Microsoft
1Teams
Jun 17, 2026
Feb 19, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Improper access control in Microsoft Teams allows an unauthorized attacker to disclose information over a network.
1Microsoft
5Dynamics 365 Guides
Dynamics 365 Remote AssistTeams+2 more
Jun 17, 2026
Aug 12, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
Heap-based buffer overflow in Microsoft Teams allows an unauthorized attacker to execute code over a network.
1Microsoft
1Teams
Jun 17, 2026
Jul 8, 2025
N/A· v4
7.0 HIGH· v3
N/A· v2
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Teams allows an authorized attacker to elevate privileges locally.
1Microsoft
1Teams
Jun 17, 2026
Jul 8, 2025
N/A· v4
3.1 LOW· v3
N/A· v2
Improper handling of insufficient permissions or privileges in Microsoft Teams allows an authorized attacker to elevate privileges over a network.
1Microsoft
1Teams
Jun 17, 2026
Dec 18, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A library injection vulnerability exists in Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, leading to a permission bypass. A malicious...Show more
A library injection vulnerability exists in Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger this vulnerability and then make use of the vulnerable application's permissions.Show less
1Microsoft
1Teams
Jun 17, 2026
Dec 18, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A library injection vulnerability exists in the WebView.app helper app of Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, leading to a...Show more
A library injection vulnerability exists in the WebView.app helper app of Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger this vulnerability and then make use of the vulnerable application's permissions.Show less
1Microsoft
1Teams
Jun 17, 2026
Dec 18, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A library injection vulnerability exists in the com.microsoft.teams2.modulehost.app helper app of Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access p...Show more
A library injection vulnerability exists in the com.microsoft.teams2.modulehost.app helper app of Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger this vulnerability and then make use of the vulnerable application's permissions.Show less
1Microsoft
1Teams
Jun 17, 2026
Aug 13, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Microsoft Teams for iOS Spoofing Vulnerability
1Microsoft
1Teams
Jun 17, 2026
Mar 12, 2024
N/A· v4
5.0 MEDIUM· v3
N/A· v2
Microsoft Teams for Android Information Disclosure Vulnerability
1Microsoft
1Teams
Aug 10, 2026
Feb 13, 2024
N/A· v4
5.0 MEDIUM· v3
N/A· v2
Microsoft Teams for Android Information Disclosure Vulnerability