High severity8.1NVD Advisory· Published Jun 9, 2026· Updated Jun 12, 2026
CVE-2026-42835
CVE-2026-42835
Description
Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.
Affected products
2Patches
Vulnerability mechanics
References
1- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42835nvdVendor Advisory
News mentions
5- Microsoft Teams for Android Vulnerability Allows Attackers to Disclose Sensitive DataCyber Security News · Jun 12, 2026
- Patch Tuesday - June 2026Rapid7 Blog · Jun 9, 2026
- Microsoft June 2026 Patch Tuesday fixes 3 zero-day, 200 flawsBleepingComputer · Jun 9, 2026
- Microsoft June 2026 Patch Tuesday fixes 6 zero-days, 200 flawsBleepingComputer · Jun 9, 2026
- Microsoft Patch Tuesday June 2026 – 198 Vulnerabilities Fixed, Including 3 Zero-daysCyber Security News · Jun 9, 2026