Microsoft has released a security update for CVE-2026-65812, a vulnerability in Microsoft Teams for Android that could allow an authorized attacker to disclose sensitive information, including user credentials.
Microsoft published the flaw on September 8, 2026, and rates it as Important. The issue affects Microsoft Teams for Android and is classified as an information disclosure vulnerability.
Microsoft said the weakness could allow sensitive information to be inserted into sent data, creating a risk that credentials may be exposed over a network under specific conditions.
This indicates that the attack can be performed remotely over a network, requires low attack complexity, and needs an attacker to have low-level privileges. However, successful exploitation also requires user interaction.
Microsoft did not specify the exact action required from a victim. This suggests an attacker may need to persuade a Teams user to interact with crafted content, a message, a shared resource, or another attacker-controlled element.
The vulnerability is linked to CWE-201, known as Insertion of Sensitive Information Into Sent Data. This class of weakness occurs when an application unintentionally includes confidential data in transmitted content.
In the Teams for Android issue, Microsoft confirmed that credentials could potentially be disclosed if the flaw is exploited. The security impact is limited to confidentiality. Microsoft assigned a High confidentiality impact, while integrity and availability impacts are rated None.
This means the vulnerability is not expected to let attackers alter Teams data, execute code, disrupt the application, or deny access to services. Its primary risk is exposing authentication-related information that could enable follow-on attacks.
Microsoft says exploitation is less likely, with no known public disclosure or in-the-wild exploitation, and no confirmed public proof-of-concept exploit. The affected Teams for Android build is 1416/1.0.0.2026133602.
Microsoft has provided an official fix through the Microsoft Teams app update channel on Google Play. Organizations should ensure that managed Android devices receive the latest Teams update as soon as possible.
Administrators should verify mobile application update policies, confirm that users are running the patched Teams version, and monitor for unusual authentication events.
Because credentials may be exposed, security teams should also review sign-in logs for suspicious access attempts, especially for accounts that use Teams on Android devices.
Ofek Levin of Enclave reported the vulnerability through coordinated vulnerability disclosure. Microsoft credited the researcher for helping identify and address the issue before confirmed exploitation was reported.
Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.
Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…
The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…
CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…
Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…
You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…
Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…