CVE-2026-42835
Microsoft Microsoft Teams for Android, teams
Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.
- CVSS
- 8.1
- EPSS
- 1.26% 66.7% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.10