DIRAS TAKE
Urgent: apply the vendor update to 1.0.0.2026133602 immediately because this vulnerability permits remote code execution without authentication. If you cannot update quickly, restrict network exposure of the app and increase monitoring for suspicious activity.
What is CVE-2026-65768?
An unauthenticated attacker can execute arbitrary code on Microsoft Teams for Android by exploiting a path traversal flaw. CVE-2026-65768 allows an attacker over the network to reach and write files outside intended directories, leading to remote code execution. The issue affects Microsoft Teams for Android versions 1.0.0 through versions before 1.0.0.2026133602; it is fixed in 1.0.0.2026133602. No authentication or user interaction is required to exploit this vulnerability, so network access to the app is sufficient for an attacker to attempt exploitation. The weakness is classified as CWE-22 (Path Traversal).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Microsoft Microsoft Teams for Android are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 1.x | 1.0.0 – before 1.0.0.2026133602 | 1.0.0.2026133602 |
Is CVE-2026-65768 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-65768
- Upgrade Microsoft Teams for Android to version 1.0.0.2026133602 immediately.
- Block or restrict network access to Microsoft Teams for Android where possible until devices are patched.
- Monitor app behavior and device logs for unexpected file writes or process launches and investigate anomalies.
- Follow Microsoft’s guidance and device management policies to ensure all users install the fixed release.
Frequently asked questions
Is CVE-2026-65768 being actively exploited?
There are no public reports of exploitation as of 2026-09-29.
Which Microsoft Teams for Android versions are affected by CVE-2026-65768?
Microsoft Teams for Android versions 1.0.0 through versions before 1.0.0.2026133602 are affected; the issue is fixed in 1.0.0.2026133602.
Is there a patch for CVE-2026-65768?
Yes. Microsoft fixed the vulnerability in Microsoft Teams for Android version 1.0.0.2026133602.
Does CVE-2026-65768 require authentication?
No. The vulnerability can be exploited without authentication, so an attacker with network access to the application can attempt to exploit it.
References
- nvd.nist.gov/vuln/detail/CVE-2026-65768
- cve.org/CVERecord?id=CVE-2026-65768
- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65768
- All Microsoft CVEs on CVE Radar
- CVEs published in September 2026