Teams August Fixes Split Cloud Assurance From Mobile Patching
Microsoft disclosed three mitigated Teams cloud flaws and an Android file-based RCE. Cloud users have no patch, but mobile fleets need version proof.
Microsoft's August 11 release disclosed three Teams cloud-service vulnerabilities: CVE-2026-65667, a CVSS 10 missing-authorization flaw; CVE-2026-62896, a CVSS 9.6 improper-authentication flaw; and CVE-2026-62918, a cryptographic-signature verification flaw rated 7.5. Microsoft says all three were fully mitigated by the company, require no customer action, were not publicly disclosed before release, and were not known to be exploited.
The same release includes a separate customer task. CVE-2026-65768 is a path-traversal remote code execution flaw in Teams for Android. An attacker can send a crafted file, but the user must open it. Microsoft lists fixed Teams build 1.0.0.2026133602, says no restart is required, and assesses exploitation as less likely with no detected exploitation. Administrators need to update and verify mobile clients while treating the cloud CVEs as transparency records, not unpatched tenant vulnerabilities.
Key Takeaways
- check_circle The CVSS 10 and 9.6 Teams cloud flaws were already mitigated by Microsoft; the vendor says customers have no action to take.
- check_circle Microsoft reports no detected exploitation and no prior public disclosure for the three cloud-service CVEs.
- check_circle CVE-2026-65768 affects Teams for Android and requires a user to open a maliciously crafted file.
- check_circle The Android RCE fix is Teams build 1.0.0.2026133602, delivered through the Google Play update path without a restart.
- check_circle Automatic update policy is not proof that every active, dormant, personally owned, or rarely connected device has crossed the fixed boundary.
- check_circle Tenant audit logs can support an investigation, but Microsoft has not published a cloud exploit window or event pattern that customers can independently validate.
One Release Contains Two Different Security Jobs
The August release groups vulnerabilities by publication date, not by who operates the affected component. CVE-2026-65667, CVE-2026-62896, and CVE-2026-62918 concern the Teams cloud service. Microsoft owns that code and says it has already fully mitigated each issue. CVE-2026-65768 concerns the Teams Android client installed on customer devices, so Microsoft provides a fixed app build and marks customer action required.
That distinction matters more than the raw score order. The highest score in the set is CVE-2026-65667 at 10.0, but there is no tenant patch to deploy. The Android flaw scores 8.8 and does require customers to prove that the corrected client reached their devices. A queue sorted only by CVSS could create urgent but impossible cloud patch work while leaving an actionable mobile update in an ordinary application backlog.
Security teams should record both kinds of disclosure. Cloud CVEs inform provider risk, assurance, and incident questions. Client CVEs drive inventory, deployment, and endpoint response. Combining them into a single status such as Teams patched hides who performed the fix, which asset crossed the safe boundary, and what evidence is available.
The Cloud CVEs Confirm Serious Classes, Not Tenant Exposure
CVE-2026-65667 is a missing-authorization issue that Microsoft says could let an unauthenticated network attacker elevate privileges. Its vector indicates high confidentiality and integrity impact with a changed security scope. CVE-2026-62896 is an improper-authentication flaw that requires low privileges first but carries similar impact. CVE-2026-62918 concerns improper verification of a cryptographic signature and could allow an unauthenticated attacker to perform spoofing.
Microsoft labels all three Critical, states that they were fully mitigated, and says users of the service have no action to take. The records also say the issues were not publicly disclosed and were not known to be exploited. Those are vendor statements about the public status at release. They are not evidence that a specific tenant was affected, and they do not establish an exploit window, attacker technique, tenant indicator, or customer-visible event.
Microsoft began issuing CVEs for critical cloud-service vulnerabilities even when customers do not need to patch, as part of a transparency policy announced in 2024. The useful response is to retain the records, map them to the provider-risk register, and ask support for incident-specific detail when other evidence creates a concern. Requiring every tenant administrator to invent a hunt for an undisclosed service-side flaw would produce confidence without a testable signal.
The Android RCE Has A Concrete File And Version Boundary
CVE-2026-65768 is different. Microsoft describes improper pathname restriction, or path traversal, in Teams for Android. The attack vector is network and does not require the attacker to hold an account privilege according to the CVSS vector, but user interaction is required. Microsoft's FAQ says the target must open a specially crafted file from the attacker to initiate code execution.
The confirmed chain therefore includes delivery and opening. Receiving a chat message or seeing a file card is not the same as successful exploitation. The public record does not identify the file format, storage path, exploit payload, resulting process behavior, or whether a second Android weakness is needed to escape the Teams application context. Defenders should not turn path traversal into unsupported claims about full device takeover.
Microsoft lists Teams for Android build 1.0.0.2026133602 as the vendor fix and points to Google Play. The remediation record says no restart is required. Microsoft assesses exploitation as less likely, with no public disclosure and no detected exploitation at release. That lower threat status supports an orderly emergency deployment, not deferral without inventory proof.
Mobile Fleet Proof Must Cover More Than Managed Phones
Start with the full set of accounts allowed to use Teams on Android, then identify enrolled corporate devices, work-profile devices, personally owned devices under mobile application management, shared devices, test phones, and devices that have not checked in recently. The relevant population is where organizational Teams data can be opened, not only the hardware shown on the primary MDM dashboard.
Push the latest Teams release through the approved application channel and query the installed application version after deployment. Microsoft identifies 1.0.0.2026133602 as the security boundary, but a newer build should also contain the fix. Keep the numeric comparison exact. Mobile version strings are easy to truncate or confuse with desktop, iOS, Teams Rooms, and Admin Agent versions, none of which are the fixed Android client named in this CVE.
Handle devices that remain below the boundary through the organization's normal mobile access controls. Options can include user notification, a short compliance deadline, blocking organizational access from a stale client where tooling supports it, and removing access for devices that never return. Document BYOD limitations. A policy that requests automatic updates cannot prove that a store-disabled, offline, storage-constrained, or abandoned phone installed one.
Investigation Needs Different Evidence For Cloud And Mobile
For the cloud CVEs, Microsoft has not supplied a tenant-facing indicator, affected interval, or audit operation tied to exploitation. Purview Audit records many Teams user and administrator activities, including membership, channel, app, and policy changes. Those logs remain valuable when a tenant observes suspicious behavior, but a clean search cannot prove that Microsoft's service-side authorization and signature flaws never touched the tenant.
If an Android user reports opening an unexpected file before the client was updated, preserve the message context, sender, file, file hash, device and Teams versions, opening time, mobile threat-defense alerts, sign-in activity, and subsequent account or file access. Do not forward the original file through ordinary chat for analysis. Use an isolated workflow that prevents another analyst from triggering the same content.
Response should follow evidence. Remove the malicious content where policy and platform controls allow, block the sender or domain when justified, update Teams, review device and account activity, and isolate or reset a device if mobile telemetry shows code execution or integrity loss. Password changes alone do not repair a compromised mobile endpoint, while a device wipe is disproportionate when the only fact is that a file arrived but was never opened.
Cloud Transparency Needs An Owner, Not A Fake Patch Ticket
Provider-managed CVEs should land with the cloud assurance or service owner. Record Microsoft's no-action and no-exploitation statements, publication date, affected service, weakness class, and any later revision. Link them to contractual notification, audit, and incident-escalation procedures. If Microsoft later changes the exploit status or contacts affected tenants, the organization then has a prepared route from vendor notice to internal response.
Client CVEs belong with endpoint and collaboration operations. Track the fixed Android build, deployment start, active-device coverage, exceptions, and the time each device or account crossed the boundary. Keep a separate unresolved list for devices with unknown versions. Unknown is not patched, but it is also not proof of compromise; it is an inventory gap that needs an owner and a deadline.
The August disclosures show why a single product name is a poor security boundary. Teams is simultaneously a cloud service, a mobile application, an identity surface, a content delivery path, and an audited collaboration workspace. Clear ownership lets administrators act precisely: accept a completed provider mitigation where the vendor owns the code, verify the endpoint update where the customer owns deployment, and investigate only from evidence that can support the conclusion.
Checklist
- Record the three cloud CVEs as Microsoft-mitigated, customer-action-not-required disclosures.
- Inventory every Android device and account that can open organizational Teams content.
- Deploy Teams for Android build 1.0.0.2026133602 or later through the approved store or management channel.
- Query installed versions and separate patched, stale, offline, and unknown devices.
- Use a documented exception and access-control path for devices that cannot update promptly.
- Preserve message, file, sender, version, and mobile telemetry when a user opened suspicious content before updating.
- Route later Microsoft revisions or tenant notices through the cloud-service incident owner.
Sources
- Microsoft Security Update Guide for CVE-2026-65667 open_in_new
- Microsoft Security Update Guide for CVE-2026-62896 open_in_new
- Microsoft Security Update Guide for CVE-2026-62918 open_in_new
- Microsoft Security Update Guide for CVE-2026-65768 open_in_new
- Microsoft explanation of cloud-service CVE transparency open_in_new
- Microsoft Teams application version history open_in_new
- Microsoft Purview audit log activities for Teams open_in_new
Continue Reading
Cisco ASA/FTD Exploitation Makes VPN Availability An Emergency
Cisco confirms active exploitation of ASA and FTD CVE-2026-20349. Exposed remote-access services need the correct hot fix and reload-focused triage.
Windows AFD Exploitation Turns Local Access Into SYSTEM Risk
Microsoft and CISA confirm exploitation of Windows AFD CVE-2026-68820. Patch affected systems and scope local access that could have become SYSTEM.
LoadMaster Exploitation Puts The Traffic Edge In Incident Scope
CISA added LoadMaster CVE-2026-8037 to KEV after exploitation reports. Operators must patch the API flaw and examine the appliance as an incident boundary.