Known Vulnerabilities for Teams by Microsoft
Listed below are 10 of the newest known vulnerabilities associated with "Teams" by "Microsoft".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-91774 json | Yao through v1.0.0-rc22 authenticates but fails to authorize the GET /user/teams/:id endpoint, allowing any logged-in user to... | Not Provided | 2026-09-15 | 2026-09-15 |
| CVE-2026-91181 json | Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 Fail to sanitize Team objects r... | Not Provided | 2026-09-14 | 2026-09-14 |
| CVE-2026-84808 json | Kimai versions before 2.65.0 contain an authorization bypass vulnerability in the REST API timesheet collection endpoint that... | Not Provided | 2026-09-02 | 2026-09-02 |
| CVE-2026-82279 json | HyperDX through 1.10.1 fails to enforce role-based access controls in team management endpoints, allowing any team member to ... | Not Provided | 2026-08-28 | 2026-08-28 |
| CVE-2026-80925 json | In the Linux kernel, the following vulnerability has been resolved: vlan: fix skb_under_panic and races when toggling HW VLA... | Not Provided | 2026-09-09 | 2026-09-11 |
| CVE-2026-80195 json | Kimai before 2.63.0 contains a business logic / improper authorization vulnerability in the team update API endpoint (PATCH /... | Not Provided | 2026-08-26 | 2026-08-26 |
| CVE-2026-76216 json | Vikunja through 2.4.0 contains a principal-type confusion vulnerability where LinkSharing principals with id N are treated as... | Not Provided | 2026-08-19 | 2026-08-20 |
| CVE-2026-72595 json | A broken access control vulnerability in BadChoice Handesk as of 2026-07-10 allows any authenticated agent to update ticket r... | Not Provided | 2026-08-11 | 2026-08-11 |
| CVE-2026-72563 json | A broken access control vulnerability in BadChoice Handesk as of 2026-07-10 allows any authenticated agent to overwrite lead ... | Not Provided | 2026-08-11 | 2026-08-11 |
| CVE-2026-69559 json | Origin validation error in Microsoft Teams for Android allows an authorized attacker to disclose information over a network. | Not Provided | 2026-09-08 | 2026-09-08 |