CYBERHAWK / CVE / CVE-2026-42835
CVE-2026-42835
HIGH
CVSS 8.1
other
The flaw
Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.
What to do
Review advisory and patch per vendor guidance.
References
In the news
- Microsoft Teams Android Flaw Could Let Attackers Disclose Sensitive Informationgbhackers.com · 2026-06-12
- Microsoft June 2026 Patch Tuesday fixes 6 zero-days, 200 flawsBleepingComputer · 2026-06-09
- High Risk Microsoft Teams Android Bug Could Leak Sensitive DataSQ Magazine · 2026-06-12