CVE-2026-26123: Microsoft Authenticator

Medium severity, CVSS 5.5. EPSS: 0.6% chance of exploitation in the next 30 days.

Cwe is not in rca categories in Microsoft Authenticator allows an unauthorized attacker to disclose information locally.

Affected products

  • Microsoft Authenticator: before 6.8.40 (fixed in 6.8.40); before 6.2511.7533 (fixed in 6.2511.7533)

Published 2026-03-10. Last modified 2026-06-17.