🔴 Critical | Source: Microsoft Security Response Center
A path traversal vulnerability in Microsoft Teams for Android allows an unauthenticated attacker to remotely execute arbitrary code on affected devices without requiring user interaction beyond having the app installed. The flaw arises from insufficient restrictions on file path handling, potentially giving attackers a foothold on corporate mobile devices. Given the widespread enterprise use of Teams on Android, the exposure across large organisations could be significant.
Security Architect’s Take: Ensure Microsoft Teams for Android is updated to the patched version across your mobile device fleet via your MDM solution (e.g. Intune) as a priority. Consider temporarily restricting Teams on Android to managed, compliant devices only through Conditional Access policies until patching is confirmed complete.
Original advisory: CVE-2026-65768 Microsoft Teams Remote Code Execution Vulnerability