CVE-2026-65768: Microsoft Teams

Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.

Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to execute code over a network.

Affected products

  • Microsoft Teams: before 1.0.0.2026133602 (fixed in 1.0.0.2026133602)

Published 2026-08-11. Last modified 2026-08-14.