CVE-2026-42835: Microsoft Teams

High severity, CVSS 8.1. EPSS: 1.2% chance of exploitation in the next 30 days.

Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.

Affected products

  • Microsoft Teams: before 1.0.76.2026111302 (fixed in 1.0.76.2026111302)

Published 2026-06-09. Last modified 2026-07-23.