CVE-2026-41615: Microsoft Authenticator

High severity, CVSS 7.4. EPSS: 1.1% chance of exploitation in the next 30 days.

Exposure of sensitive information to an unauthorized actor in Microsoft Authenticator allows an unauthorized attacker to disclose information over a network.

Affected products

  • Microsoft Authenticator: before 6.8.47 (fixed in 6.8.47); before 6.2605.2973 (fixed in 6.2605.2973)

Published 2026-05-14. Last modified 2026-06-17.