CVE-2026-42835: Microsoft Teams
High severity, CVSS 8.1. EPSS: 1.2% chance of exploitation in the next 30 days.
Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.
Affected products
- Microsoft Teams: before 1.0.76.2026111302 (fixed in 1.0.76.2026111302)
Published 2026-06-09. Last modified 2026-07-23.