THREAT BRIEFING · 02.10.2026 DEENFRES

Practice & Implementation

Microsoft Teams: Android Path Traversal Runs Attacker Code

By Benedikt Langer · August 18, 2026 · 7 min read

On August 11, 2026, the NVD added CVE-2026-65768. Microsoft Teams for Android allows an unauthorized attacker to exploit path traversal and execute code over the network. Microsoft rates the flaw at CVSS 8.8 with user interaction required. The NVD assigns 9.8 with no user interaction. On August 12, CISA recorded no known exploitation.

Key Takeaways

  • Path traversal, CWE-22. Microsoft Teams for Android. Unauthorized attacker, code execution over the network. NVD entry published August 11, 2026, last modified August 14, 2026. Advisory: Microsoft Security Update Guide.
  • 8.8 and 9.8 side by side. Microsoft: CVSS 3.1 8.8 with UI:R. NVD: 9.8 with UI:N. Same CVE, two vectors.
  • CISA SSVC August 12, 2026. Exploitation: none, automatable: no, technical impact: total.
  • Threshold 1.0.0.2026133602. The NVD lists Teams for Android below this version. The Windows monthly update does not change this Store client.

Related: LoadMaster on the KEV List: Patch Available Since June

What is CVE-2026-65768? The NVD describes path traversal (CWE-22) in Microsoft Teams for Android. An unauthorized attacker can execute code over the network. Microsoft assigns CVSS 8.8 with user interaction required; the NVD assigns 9.8 with no user interaction. The threshold is versionEndExcluding 1.0.0.2026133602. On August 12, 2026, CISA recorded no known exploitation.

Microsoft outlines a path – then comes the code

The NVD (National Vulnerability Database) published CVE-2026-65768 on August 11, 2026 at 17:18 UTC. The short description reads: Improper limitation of a pathname to a restricted directory (‘path traversal’) in Microsoft Teams for Android allows an unauthorized attacker to execute code over a network. The last modification to the entry is dated August 14, 2026, 13:27 UTC.

As the vendor advisory, the NVD points to the Microsoft Security Update Guide under CVE-2026-65768. The weakness is classified as CWE-22. The NVD names no concrete click path, no file extension, and no public exploit. Anyone logging such a sequence in a ticket would be going beyond the published text.

Definition · Path Traversal in Teams for Android

What is CVE-2026-65768? The NVD describes an improper limitation of a pathname to a restricted directory (CWE-22) in Microsoft Teams for Android. This allows an unauthorized attacker to execute code over a network. The NVD lists microsoft:teams on Android below 1.0.0.2026133602 as the affected configuration.

The affected product line in the NVD configuration is microsoft:teams on the Android platform. Other Teams clients are not covered by this entry. An inventory that only counts Windows installations will miss the listed configuration entirely.

Two Scores, One Product Line

Microsoft supplies the NVD with a CVSS 3.1 secondary metric of 8.8 (High). The vector reads AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. The NVD, in turn, sets a primary metric of 9.8 (Critical): AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The visible difference sits in UI: Microsoft assumes user interaction is required, while the NVD assumes none.

Both figures belong in the ticket. Anyone adopting only the 8.8 ignores the NVD’s reading; anyone adopting only the 9.8 disregards Microsoft’s interaction assumption. Confidentiality, Integrity, and Availability are rated High in both vectors, and Scope remains Unchanged.

8.8

Microsoft CVSS 3.1 High. Vector AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H (NVD secondary metric, as of August 14, 2026).

9.8

NVD CVSS 3.1 Critical. Vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H (primary metric, as of August 14, 2026).

The threshold is 1.0.0.2026133602

The NVD lists the CPE cpe:2.3:a:microsoft:teams:*:*:*:*:*:android:*:* with versionEndExcluding 1.0.0.2026133602. Every Android build below this number counts as affected under the entry. The NVD names no older safe lower bound. Inventory checks therefore mean: read the build, compare it against the threshold, roll out the update, then read the build again.

This number lives in the store package. A Windows monthly update does not touch the Android client. MDM reports that only track the desktop state leave the listed configuration exposed. Unmanaged service phones and BYOD devices belong in the same table, otherwise a blind spot remains.

CISA sees no exploitation so far

On August 12, 2026, CISA added an SSVC assessment to the NVD entry. Exploitation is set to none. Automatable is set to no. Technical impact is set to total. The third value matches the High rating for confidentiality, integrity, and availability: if the attack succeeds, the technical damage is complete.

CISA SSVC, August 12, 2026

exploitation: none. automatable: no. technical impact: total. A status of none means: CISA documented no known exploitation as of that day. That is no carte blanche for the remaining unpatched systems.

None is the documented state of knowledge as of August 12. CISA has not added the CVE to its Known Exploited Vulnerabilities Catalog. No deadline under BOD 26-04 (Binding Operational Directive) applies to this entry. That does not let the remaining systems off the hook – it merely removes the federal deadline as an additional driver.

MDM Must Prove the Build Number

The first step is a complete Android inventory. Every device needs a package name, build number, MDM status, and owner. Corporate-owned devices go at the top. Unmanaged devices follow as their own block – not as a footnote.

Android Teams Inventory

  • ✓List MDM-managed and uncontrolled devices by Microsoft Teams package and build number.
  • ✓Check every build against the NVD threshold 1.0.0.2026133602.
  • ✓Trigger a store update or Managed Google Play rollout, then re-read the new build.
  • ✓Track devices without MDM as an open remainder.
  • ✓Record both CVSS vectors and the CISA SSVC decision from August 12, 2026 in the ticket.

For leadership, one sentence is enough. Is Microsoft Teams for Android on 1.0.0.2026133602 or higher everywhere? Does the remainder sit inside MDM or outside it? Until the table shows the build number, the CVE stays open.

Frequently Asked Questions

Every question is locked. A tap unlocks the answer.

Does CVE-2026-65768 affect the desktop client?

The NVD (National Vulnerability Database) currently lists only microsoft:teams on Android in its configuration. Other clients do not appear in this entry. A desktop inventory is no substitute for checking the Android client.

Why are 8.8 and 9.8 shown side by side?

Microsoft rates it 8.8 with user interaction (UI:R). The NVD assigns 9.8 with no user interaction required (UI:N). Both metrics are documented in the NVD entry dated August 14, 2026.

Is this vulnerability being actively exploited?

The CISA SSVC assessment (CISA’s SSVC decision model, August 12, 2026) sets exploitation to none. The NVD (National Vulnerability Database) lists no public exploit, and this CVE does not appear in the KEV catalog (CISA’s Known Exploited Vulnerabilities).

Which version closes the gap?

The NVD has set versionEndExcluding 1.0.0.2026133602 for Teams for Android. Builds below this number are considered affected. Confirming the new status requires re-checking the build number.

Is the monthly Windows update enough?

No. The listed configuration is the Android store client. A Windows monthly update does not change that package. The fix is delivered via the Store or Managed Google Play.

Editor’s Picks

Editor’s PickBOD 26-04: Prioritizing KEV and EPSS Correctly

More from the MBF Media Network

Digital ChiefsFalse Sense of Security: When Cyber Police Fail to Act in a Real Emergency

Image source: AI-generated (August 2026)

Translated from the German original using artificial intelligence. The German version is authoritative.

Further reading

A magazine by Evernine Media GmbH