CyberRota Analysis
AI-GeneratedMicrosoft Teams for Android is vulnerable to cross-site scripting due to improper input neutralization during web page generation, allowing authorized attackers to execute spoofing attacks over the network. This high-severity vulnerability can compromise user trust and data integrity. Organizations using Microsoft Teams on Android should prioritize patching this issue to mitigate potential security risks.
CVE
CVE-2026-65767
Severity
HIGH
CVSS
8.8
EPSS
0.44%
Microsoft Android
Original NVD Description
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allows an authorized attacker to perform spoofing over a network.
Related CVEs
Other vulnerabilities affecting the same vendor(s)