𝕏 Bug Bounty Writeups 𝕏[verified]@bountywriteupsDisclosure
The title announces CVE‑2026‑26123, a Microsoft Authenticator flaw that allows full account takeover via an unclaimed deep link, but the excerpt does not provide technical details, evidence of exploitation, or mitigation information.
I'M H4CK3R 42[verified]@luckyhacker43PoC
The post announces a successful account takeover via an unclaimed deep link in Microsoft Authenticator, referencing a proof‑of‑concept article and a vendor patch advisory.
kokumօtօ[verified]@__kokumotoDisclosure
Microsoft Authenticator’s CVE‑2026‑26123 allows login code leakage via deep links on Android and iOS; the flaw is low‑severity (CVSS 3.1) and has already been patched.
DFIR Radar[verified]@DFIR_RadarPatch
A newly disclosed Microsoft Authenticator vulnerability (CVE-2026-26123) lets malicious apps intercept authentication tokens during QR setup, enabling full account takeover without 2FA; users are urged to update immediately.
DFIR Radar[verified]@DFIR_RadarPoC
The write‑up reveals Microsoft Authenticator’s CVE‑2026‑26123, showing a malicious deep‑link proof of concept that can lead to full account takeover, with detailed technical analysis but no evidence of active exploitation or a patch.
Voidwalker[verified]@JustWantToQ1General
A user inquires whether their device is affected by CVE-2026-26123 and wonders about patching issues, but offers no concrete evidence or technical details.
Zeeshan Khan ⚡🜏 | InfoSec & Chaos[verified]@zeeshankghouriGeneral
The brief text only introduces CVE-2026-26123 with a mention of a full account takeover story, but provides no supporting technical or exploit details.
VulnTracker[verified]@vuln_trackerDisclosure
The tweet announces a new vulnerability (CVE-2026-26123) involving an unclaimed deep link in Microsoft Authenticator that could enable full account takeover, but provides no PoC, exploitation evidence, or patch details.