CVE-2026-21535Disclosure(microsoft / teams)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch microsoft teams systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper access control in Microsoft Teams allows an unauthorized attacker to disclose information over a network.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • teams

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • Peaked 2d ago at 3 mentions (2026-02-20); latest day: 1
  • 7 total mentions across 4 days

Affected systems

Vendors
Products
teams

1 version affected across 1 product

Deep dive

Activity timeline7 mentions / 4d
01223Mentions · 2026-02-19: 1Mentions · 2026-02-20: 3Mentions · 2026-02-21: 2Mentions · 2026-05-13: 1Patch / Workaround · 2026-02-20: 1Patch / Workaround · 2026-05-13: 1Technical Details · 2026-02-19: 1Technical Details · 2026-02-20: 3Technical Details · 2026-02-21: 1Technical Details · 2026-05-13: 102-1902-2002-2105-13
Signal classification2 categories
Disclosure
571.4%
Patch
228.6%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-02-191
Disclosure1
2026-02-203
Disclosure2Patch1
2026-02-212
Disclosure2
2026-05-131
Patch1
Full discourse7 posts
  • kawn@kawn2020
    Disclosure

    #securityupdate #microsoft #定例外 2026. 2.20 Microsoft Teams の情報漏えいの脆弱性 CVE-2026-21535 Security Vulnerability リリース日: Feb 20, 2026 - マイクロソフト https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21535

    Post summary

    Microsoft announced CVE-2026-21535 as a security vulnerability affecting Microsoft Teams, noting an information‑leak issue but providing no further technical details or mitigation information.

    10100113
    89 followersView on X
  • Rory J Bernier@RoryCrave
    Patch

    Microsoft just patched a high-severity flaw in Teams (CVE-2026-21535, CVSS 8.2) that allowed unauthenticated attackers to access sensitive network data remotely. No credentials needed. No user interaction needed. No elevated privileges needed. Just network access. The good news: it was a server-side fix, so no action required from Teams users or admins. Already patched. This comes on top of an already brutal February Patch Tuesday with 6 actively exploited zero-days across Windows Shell, MSHTML, Word, RDP, and more. https://www.techzine.eu/news/security/138956/microsoft-closes-teams-leak-that-allowed-access-without-authentication/ #InfoSec #CyberSecurity #Microsoft #Teams #PatchTuesday

    Post summary

    Microsoft has released a patch for CVE-2026-21535, a high‑severity Teams flaw allowing unauthenticated remote access; users and admins need not take action as the fix is server‑side.

    0001060
    2.9K followersView on X
  • Vito Botta@vitobotta
    Patch

    Unauthenticated info disclosure in Microsoft Teams. CVE-2026-21535. No login needed, just network access, and you can pull sensitive data from a tool that sits open on every corporate laptop. Part of Patch Tuesday this month, 120+ CVEs total, no zero-days. Patch your Teams installs. https://www.bleepingcomputer.com/news/microsoft/microsoft-may-2026-patch-tuesday-fixes-120-flaws-no-zero-days/

    Post summary

    Microsoft Teams CVE-2026-21535 is an unauthenticated info disclosure disclosed in Patch Tuesday; no active exploitation reported, but teams should apply the available patch.

    0000086
    978 followersView on X
  • kawn@kawn2020
    Disclosure

    #securityupdate #microsoft #定例外 CVE-2026-21535 Security Vulnerability 影響: 情報漏えい 最大深刻度: 緊急 CVSS:3.1 8.2 / 7.1 悪用可能性 ・一般に公開: No ・悪用: No ・Exploitability assessment: 悪用される可能性は非常に低い https://x.com/kawn2020/status/2025028103609909582

    Post summary

    The tweet discloses CVE-2026-21535 as an information‑leak vulnerability with high CVSS scores, but provides no PoC, exploit, or patch details.

    0000049
    89 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-21535 Improper access control in Microsoft Teams allows an unauthorized attacker to disclose information over a network. https://www.cve.org/CVERecord?id=CVE-2026-21535

    Post summary

    The statement provides a brief disclosure of an improper access control vulnerability in Microsoft Teams that could enable information disclosure over the network.

    00000124
    56.4K followersView on X
  • Aakash Rahsi@rahsi_aaka
    Disclosure

    CVE-2026-21535 | Microsoft Teams Information Disclosure Vulnerability https://www.aakashrahsi.online/post/cve-2026-21535 https://t.co/I09LqwQjWi

    Post summary

    A new CVE (CVE‑2026‑21535) has been identified for an information disclosure vulnerability in Microsoft Teams, but no PoC, exploit, active exploitation, patch, or debunking information is provided.

    0000023
    2 followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2026-21535** pertains to an **improper access control** vulnerability within **Microsoft Teams**, a widely used collaboration platform. This flaw allows an **unauthorized attacker** to **disclose sensitive information** over the network without requiring user privileges or interaction. The core issue stems from insufficient validation or enforcement of access permissions within the application, enabling malicious actors to access data they should not have rights to. #Cybersecurity #CVE #HighSeverity #SecurityAlert #RemoteCodeExecution #Microsoft https://cvetodo.com/cve/CVE-2026-21535

    Post summary

    The post announces CVE-2026-21535, an improper access control vulnerability in Microsoft Teams that could allow sensitive data disclosure without privileged access; no PoC, exploit, active exploitation, or patch is mentioned.

    0000056
    20 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftteams---

Explore more