• PATCH AVAILABLE

CVE-2026-65768: pre-auth remote code execution in Microsoft Microsoft Teams for Android

An unauthenticated attacker can execute arbitrary code on Microsoft Teams for Android by exploiting a path traversal flaw. CVE-2026-65768 allows an attacker over the network to reach and write files outside intended directories, leading to remote code execution. The issue affects Microsoft Teams for Android versions 1.0.0 through versions before 1.0.0.2026133602; it is fixed in 1.0.0.2026133602. No authentication or user interaction is required to exploit this vulnerability, so network access to the app is sufficient for an attacker to attempt exploitation.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
9.8CRITICAL
EPSS
0.00939
CWE
CWE-22
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: apply the vendor update to 1.0.0.2026133602 immediately because this vulnerability permits remote code execution without authentication. If you cannot update quickly, restrict network exposure of the app and increase monitoring for suspicious activity.

What is CVE-2026-65768?

An unauthenticated attacker can execute arbitrary code on Microsoft Teams for Android by exploiting a path traversal flaw. CVE-2026-65768 allows an attacker over the network to reach and write files outside intended directories, leading to remote code execution. The issue affects Microsoft Teams for Android versions 1.0.0 through versions before 1.0.0.2026133602; it is fixed in 1.0.0.2026133602. No authentication or user interaction is required to exploit this vulnerability, so network access to the app is sufficient for an attacker to attempt exploitation. The weakness is classified as CWE-22 (Path Traversal).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Microsoft Microsoft Teams for Android are affected?

BRANCHAFFECTEDFIXED
1.x1.0.0 – before 1.0.0.20261336021.0.0.2026133602

Is CVE-2026-65768 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-65768

  1. Upgrade Microsoft Teams for Android to version 1.0.0.2026133602 immediately.
  2. Block or restrict network access to Microsoft Teams for Android where possible until devices are patched.
  3. Monitor app behavior and device logs for unexpected file writes or process launches and investigate anomalies.
  4. Follow Microsoft’s guidance and device management policies to ensure all users install the fixed release.

Frequently asked questions

Is CVE-2026-65768 being actively exploited?

There are no public reports of exploitation as of 2026-09-29.

Which Microsoft Teams for Android versions are affected by CVE-2026-65768?

Microsoft Teams for Android versions 1.0.0 through versions before 1.0.0.2026133602 are affected; the issue is fixed in 1.0.0.2026133602.

Is there a patch for CVE-2026-65768?

Yes. Microsoft fixed the vulnerability in Microsoft Teams for Android version 1.0.0.2026133602.

Does CVE-2026-65768 require authentication?

No. The vulnerability can be exploited without authentication, so an attacker with network access to the application can attempt to exploit it.

References