Description
Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing over a network.
Published: 2026-08-06
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Microsoft Teams does not properly verify the cryptographic signature on messages or calls, allowing an attacker who can send data over the network to impersonate legitimate participants. The lack of signature validation means the attacker could inject deceptive content or initiate calls that appear to come from trusted users, potentially enabling phishing, social engineering, or other malicious interactions within Teams. This flaw does not provide direct code execution but severely undermines authentication integrity and could affect the confidentiality of private communications.

Affected Systems

The vulnerability impacts Microsoft Teams across all installations, as no specific version details are disclosed in the CNA data. The CNA lists Microsoft Teams as the affected product, and the CPE entry indicates all versions are potentially affected until a patch is applied. System administrators should verify that their Teams deployments are running the latest releases or have applied the fix identified in the Microsoft Security Response Center update guide.

Risk and Exploitability

The CVSS score of 7.5 indicates high severity, and while an EPSS score is not available, the flaw is exploitable over a network where the attacker can send crafted packets. The vulnerability is not currently listed in CISA’s KEV catalog. Based on the description, the attack vector is most likely remote over the network; the attacker must be able to send or receive data to the Teams client. Successful exploitation would allow impersonation but does not grant additional system privileges.

Generated by OpenCVE AI on August 7, 2026 at 01:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft Teams update that addresses the signature verification issue, as documented in the Microsoft Security Response Center update guide.
  • Verify that all clients and servers are using the latest TLS version and certificate pinning to reduce the chance of man‑in‑the‑middle attacks.
  • Consider disabling or limiting legacy authentication mechanisms and enforcing multi‑factor authentication to raise the barrier for credential‑based attacks.

Generated by OpenCVE AI on August 7, 2026 at 01:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 07 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Description Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing over a network.
Title Microsoft Teams Spoofing Vulnerability
First Time appeared Microsoft
Microsoft teams
Weaknesses CWE-347
CPEs cpe:2.3:a:microsoft:teams:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft teams
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C'}


cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-07T01:00:10.471Z

Reserved: 2026-07-14T21:25:21.036Z

Link: CVE-2026-62918

cve-icon Vulnrichment

Updated: 2026-08-07T01:00:06.928Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T01:30:04Z

Weaknesses
  • CWE-347

    Improper Verification of Cryptographic Signature