CVE-2026-65812ImportantRevised 15 Sep
Microsoft Teams for Android Information Disclosure Vulnerability
Assessment
Insertion of sensitive information into sent data in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.
- Severity
- Important
- CVSS base score
- 6.8CVSS:3.1/
AV:N/ AC:L/ PR:L/ UI:R/ S:C/ C:H/ I:N/ A:N/ E:U/ RL:O/ RC:C - Impact
- Information Disclosure
- EPSS, next 30 days
- 0.9%Higher than 57.8% of scored CVEs · FIRST model run 26 Sep 2026 · about EPSS
- Exploitability
- Exploitation Less Likely
- Publicly disclosed
- No
- Customer action
- Required: apply the update
- Component
- Microsoft Teams for Android
- Weakness
- CWE-201: Insertion of Sensitive Information Into Sent Data
- Issued by
- Microsoft
- Published
- 8 Sep 2026 · September 2026
- Last revised
- 15 Sep 2026Corrected fix build number. Informational change only.
Updates that fix it
0 KBsNo KB listed
MSRC lists no downloadable update, which usually means a service-side fix or a release-notes update. Check the MSRC advisory.
Affected products
Microsoft Office1 affected product
- Microsoft Teams for Android