CVE-2026-65768: Microsoft Teams Remote Code Execution Vulnerability
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to execute code over a network.
Other sources
Microsoft Teams Remote Code Execution Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.0.0.2026133602
Event History
Frequently Asked Questions
What is the severity of CVE-2026-65768?
The severity of CVE-2026-65768 is rated high with a score of 8.8.
What does CVE-2026-65768 affect?
CVE-2026-65768 affects Microsoft Teams for Android.
How does CVE-2026-65768 work?
CVE-2026-65768 exploits a path traversal vulnerability that allows unauthorized code execution over a network.
What are the potential impacts of CVE-2026-65768?
The potential impacts of CVE-2026-65768 include unauthorized access to sensitive data and remote code execution.
How do I fix CVE-2026-65768?
Fixing CVE-2026-65768 involves updating Microsoft Teams for Android to the latest version provided by Microsoft.