CVE-2026-26123General(microsoft / authenticator)

MEDIUMCVSS 5.5 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch microsoft authenticator systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Cwe is not in rca categories in Microsoft Authenticator allows an unauthorized attacker to disclose information locally.

4.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-939

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • authenticator

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 23 mentions across 16 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 9 signals
  • Technical details provided in 13 signals
  • General: 8 classified signals
  • Disclosure: 7 classified signals
  • Peaked 12d ago at 4 mentions (2026-03-13); latest day: 1
  • 23 total mentions across 16 days

Affected systems

Vendors
Products
authenticator

Deep dive

Activity timeline23 mentions / 16d
01234Mentions · 2026-03-10: 2Mentions · 2026-03-11: 1Mentions · 2026-03-12: 2Mentions · 2026-03-13: 4Mentions · 2026-03-14: 1Mentions · 2026-03-17: 1Mentions · 2026-03-18: 1Mentions · 2026-03-19: 1Mentions · 2026-03-23: 1Mentions · 2026-03-25: 2Mentions · 2026-03-26: 1Mentions · 2026-03-28: 2Mentions · 2026-03-31: 1Mentions · 2026-04-05: 1Mentions · 2026-06-12: 1Mentions · 2026-09-11: 1PoC Mentioned / Linked · 2026-03-28: 1PoC Mentioned / Linked · 2026-06-12: 1PoC Mentioned / Linked · 2026-09-11: 1Exploit Tool / Code · 2026-06-12: 1Patch / Workaround · 2026-03-12: 1Patch / Workaround · 2026-03-13: 3Patch / Workaround · 2026-03-14: 1Patch / Workaround · 2026-03-23: 1Patch / Workaround · 2026-03-28: 1Patch / Workaround · 2026-06-12: 1Patch / Workaround · 2026-09-11: 1Technical Details · 2026-03-10: 2Technical Details · 2026-03-11: 1Technical Details · 2026-03-12: 1Technical Details · 2026-03-13: 3Technical Details · 2026-03-23: 1Technical Details · 2026-03-26: 1Technical Details · 2026-03-28: 2Technical Details · 2026-03-31: 1Technical Details · 2026-06-12: 103-1003-1103-1203-1303-1403-1703-1803-1903-2303-2503-2603-2803-3104-0506-1209-11
Signal classification5 categories
General
834.8%
Disclosure
730.4%
Patch
521.7%
PoC
28.7%
Exploit
14.3%
Referenced assets18 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-102
Disclosure2
2026-03-111
Disclosure1
2026-03-122
Disclosure1General1
2026-03-134
Disclosure1General1Patch2
2026-03-141
Patch1
2026-03-171
General1
2026-03-181
General1
2026-03-191
General1
2026-03-231
Patch1
2026-03-252
Disclosure1General1
2026-03-261
Disclosure1
2026-03-282
Patch1PoC1
2026-03-311
General1
2026-04-051
General1
2026-06-121
Exploit1
2026-09-111
PoC1
Full discourse20 posts
  • 𝕏 Bug Bounty Writeups 𝕏@bountywriteups
    Disclosure

    Microsoft Authenticator’s Unclaimed Deep Link: A Full Account Takeover Story (CVE-2026–26123) https://infosecwriteups.com/microsoft-authenticators-unclaimed-deep-link-a-full-account-takeover-story-cve-2026-26123-e0409a920a02?source=rss------bug_bounty-5 #bugbounty #bugbountytips #bugbountytip

    Post summary

    The title announces CVE‑2026‑26123, a Microsoft Authenticator flaw that allows full account takeover via an unclaimed deep link, but the excerpt does not provide technical details, evidence of exploitation, or mitigation information.

    120061485.8K
    40.3K followersView on X
  • I'M H4CK3R 42@luckyhacker43
    PoC

    Microsoft Authenticator's Unclaimed Deep Link: A Full Account Takeover Story by Khaled Mohamed 🤯🔥 CVE-2026-26123 🔗 https://www.cve.org/CVERecord?id=CVE-2026-26123 🔗 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26123 👨‍💻 Khaled Mohamed (in/khaledsec) 🔗 https://infosecwriteups.com/microsoft-authenticators-unclaimed-deep-link-a-full-account-takeover-story-cve-2026-26123-e0409a920a02 🔗 Join team 👉https://t.me/luckyhacker42 https://t.co/rB7YB0oCeY

    Post summary

    The post announces a successful account takeover via an unclaimed deep link in Microsoft Authenticator, referencing a proof‑of‑concept article and a vendor patch advisory.

    05028182.4K
    5.0K followersView on X
  • kokumօtօ@__kokumoto
    Disclosure

    Microsoft Authenticatorにログインコード漏洩の脆弱性(CVE-2026-26123)。AndroidとiOSの両OS向けアプリに影響。同一端末上の悪性アプリに対するディープリンクで発現。CVSSスコア3.1。修正済み。 https://www.malwarebytes.com/blog/news/2026/03/microsoft-authenticator-could-leak-login-codes-update-your-app-now

    Post summary

    Microsoft Authenticator’s CVE‑2026‑26123 allows login code leakage via deep links on Android and iOS; the flaw is low‑severity (CVSS 3.1) and has already been patched.

    07033112.2K
    7.3K followersView on X
  • Alessandro Antonucci 𝕏@techworldaleant
    Patch

    🚨Una vulnerabilità di sicurezza identificata come CVE-2026-26123 mette a rischio gli utenti di Microsoft Authenticator su sistemi Android e iOS 📌Per proteggere i propri dati, gli esperti consigliano di aggiornare l'app https://www.malwarebytes.com/blog/news/2026/03/microsoft-authenticator-could-leak-login-codes-update-your-app-now

    Post summary

    The post warns about CVE-2026-26123 affecting Microsoft Authenticator on Android and iOS and advises users to update the app as the remedy.

    00031181
    792 followersView on X
  • Brian in Pittsburgh@arekfurt
    General

    😄🤦 https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-26123 https://t.co/BzEfgs1Iud

    Post summary

    The post only links to the Microsoft update page for CVE‑2026‑26123 without further commentary or technical details.

    00030542
    6.9K followersView on X
  • DFIR Radar@DFIR_Radar
    Patch

    CVE-2026-26123: Microsoft Authenticator failed to claim its ms-msa:// deep link, allowing malicious apps to intercept authentication tokens during QR setup and achieve full account takeover bypassing 2FA. Update immediately. #DFIR_Radar https://t.co/6b69F7REk6

    Post summary

    A newly disclosed Microsoft Authenticator vulnerability (CVE-2026-26123) lets malicious apps intercept authentication tokens during QR setup, enabling full account takeover without 2FA; users are urged to update immediately.

    10010174
    1.2K followersView on X
  • Rushikesh Khaire@Rushikesh6824
    Exploit

    Microsoft Authenticator’s Unclaimed Deep Link: A Full Account Takeover Story (CVE-2026–26123) https://khaledsec.medium.com/microsoft-authenticators-unclaimed-deep-link-a-full-account-takeover-story-cve-2026-26123-e0409a920a02?sk=df506976e7c2d15fd29e70725873f6e2

    Post summary

    The Medium article demonstrates CVE‑2026‑26123 via an unclaimed deep link, providing PoC code and mitigation, but does not confirm live exploitation.

    0001038
    5 followersView on X
  • DFIR Radar@DFIR_Radar
    PoC

    Source: https://infosecwriteups.com/microsoft-authenticators-unclaimed-deep-link-a-full-account-takeover-story-cve-2026-26123-e0409a920a02?source=rss----7b722bfd1b8d---4

    Post summary

    The write‑up reveals Microsoft Authenticator’s CVE‑2026‑26123, showing a malicious deep‑link proof of concept that can lead to full account takeover, with detailed technical analysis but no evidence of active exploitation or a patch.

    00010155
    1.0K followersView on X
  • ‘BBWriteups’@bbwriteup
    General

    "Microsoft Authenticator’s Unclaimed Deep Link: A Full Account Takeover Story (CVE-2026–26123)" by Khaled Mohamed #BugBounty #Cybersecurity #Hacking #InfoSec https://infosecwriteups.com/microsoft-authenticators-unclaimed-deep-link-a-full-account-takeover-story-cve-2026-26123-e0409a920a02

    Post summary

    The snippet references a vulnerability (CVE‑2026‑26123) in Microsoft Authenticator described as a full account takeover, but lacks explicit PoC, exploit code, or patch details.

    0001064
    546 followersView on X
  • Voidwalker@JustWantToQ1
    General

    @MsftSecIntel Does it have to do with CVE-2026-26123? I just seen this now, but I'm wondering if my device's being blocked because it just can't be patched on this shit phone and the version is too outdated or something.. idk.

    Post summary

    A user inquires whether their device is affected by CVE-2026-26123 and wonders about patching issues, but offers no concrete evidence or technical details.

    1000025
    2.3K followersView on X
  • Zeeshan Khan ⚡🜏 | InfoSec & Chaos@zeeshankghouri
    General

    Microsoft Authenticator’s Unclaimed Deep Link: A Full Account Takeover Story (CVE-2026–26123) https://khaledsec.medium.com/microsoft-authenticators-unclaimed-deep-link-a-full-account-takeover-story-cve-2026-26123-e0409a920a02?sk=df506976e7c2d15fd29e70725873f6e2

    Post summary

    The brief text only introduces CVE-2026-26123 with a mention of a full account takeover story, but provides no supporting technical or exploit details.

    0000098
    1.7K followersView on X
  • Aakash Rahsi@rahsi_aaka
    General

    CVE-2026-26123 | Microsoft Authenticator Information Disclosure Vulnerability https://www.aakashrahsi.online/post/cve-2026-26123 https://t.co/6vzvuYN6li

    Post summary

    The text provides a minimal CVE reference with a brief vulnerability label and links to external resources, but lacks detailed exploitation, patch, or proof‑of‑concept information.

    0000033
    1 followersView on X
  • VulnTracker@vuln_tracker
    Disclosure

    @bountywriteups @bountywriteups When your 2FA app becomes the attack vector. CVE-2026-26123 - an unclaimed deep link in Microsoft Authenticator gave attackers a path to full account takeover. The irony of your security layer being the weakest link. https://vulntracker.io

    Post summary

    The tweet announces a new vulnerability (CVE-2026-26123) involving an unclaimed deep link in Microsoft Authenticator that could enable full account takeover, but provides no PoC, exploitation evidence, or patch details.

    0000097
    460 followersView on X
  • kotaro@サイバーセキュリティ情報発信@ngsk_ciso
    Patch

    「MFAを設定してるから安心」——その気持ち、すごくわかります。 ただ、3月の月例パッチでひっそり修正された脆弱性(CVE-2026-26123)があって、Microsoft Authenticatorアプリ自体に問題があったことが明らかになりました。 悪意あるアプリがサインインの流れに割り込んで、認証情報を傍受できてしまう可能性があったようです。 とはいえ、対応はシンプルです。 スマートフォンのMicrosoft Authenticatorを最新版に更新するだけ。 App StoreやGoogle Playで「自動アップデート」が有効になっていれば、もう対応済みの可能性が高いです。 一度アプリのバージョンを確認してみると安心かも。 社員に配布しているスマホがある場合は、MDMで確認するか、朝礼等で一言アナウンスするだけで十分だと思います。 MFAは引き続き有効な対策ですよ。アプリを最新に保ちながら使い続けましょう。 #社内SE #セキュリティ 出典: https://www.helpnetsecurity.com/2026/03/11/march-2026-patch-tuesday/

    Post summary

    The message exposes CVE‑2026‑26123 affecting Microsoft Authenticator, warns of malicious interception of sign‑in flows, and urges users to update the app—a patch‑centric advisory with no reported active exploitation or PoC.

    0000060
    22 followersView on X
  • Stuart 🇨🇷@stooee_
    General

    After analyzing 50% of vulnerabilities from past week, CVE-2026-26123 has 7 articles published from different internet sources, no other cve has these many articles. More information here: https://cves.st00ee.com/ #vulnerability #CyberSecurity #ThreatIntel #CVE #SecurityAlert

    Post summary

    The post highlights that CVE-2026-26123 has attracted significant media coverage and provides a link for more information, but it does not include technical details, exploitation evidence, or remediation guidance.

    0000044
    72 followersView on X
  • Stuart 🇨🇷@stooee_
    General

    After analyzing 38% of vulnerabilities from past week, CVE-2026-26123 has 7 articles published from different internet sources, no other cve has these many articles. More information here: https://cves.st00ee.com/ #vulnerability #CyberSecurity #ThreatIntel #CVE #SecurityAlert

    Post summary

    The tweet highlights that CVE‑2026‑26123 has attracted attention across multiple articles, but it provides no details on exploitation, patches, PoC, or technical specifics.

    0000033
    72 followersView on X
  • Esto es DxT@estoesdxt_es
    Patch

    🔐 Falla CVE-2026-26123 expone códigos de Microsoft Authenticator en iOS y Android; la última actualización corrige el manejo de enlaces profundos ⚠️ #Ciberseguridad #MicrosoftAuthenticator #Actualización https://www.estoesdxt.es/si-usas-microsoft-authenticator-en-ios-o-android-actualiza-ya-por-una-falla-que-filtra-codigos/

    Post summary

    CVE‑2026‑26123 allowed Microsoft Authenticator codes to be exposed on iOS and Android; Microsoft released an update that corrects deep‑link handling to mitigate the issue.

    0000054
    4 followersView on X
  • Laberinto Digital@ZamnaX_89
    Disclosure

    El guardián ha dejado la puerta entornada. Se detectó una vulnerabilidad crítica en Microsoft Authenticator (CVE-2026-26123). Un error en el manejo de deep links permite que apps maliciosas en el mismo dispositivo intercepten tus códigos de acceso y enlaces de inicio de sesión. No es una teoría; es un riesgo real para cuentas personales y entornos corporativos BYOD. Si el atacante controla el enlace, controla tu identidad. La orden es inmediata: actualiza la app en iOS y Android. En este Laberinto, el parche es la única redención. No permitas que tu herramienta de seguridad sea tu mayor debilidad. #Microsoft #CyberSecurity #MFA #CVE2026 #LaberintoDigital

    Post summary

    A critical vulnerability (CVE-2026-26123) in Microsoft Authenticator allows malicious apps on the same device to intercept authentication codes via faulty deep-link handling; users are urged to update the iOS and Android app immediately.

    0000048
    7 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Microsoft Authenticator Flaw on Android and iOS Could Leak MFA Codes to Malicious Apps A patched flaw tracked as CVE-2026-26123 in Microsoft Authenticator could let a malicious app on the same device intercept deep-link based login data, including one-time codes and sign-in links, if a user mistakenly routes authentication to the wrong app. This matters because Authenticator is widely deployed for MFA, so even a local interception weakness can undermine account protection across enterprise email, cloud, and identity workflows. 🎯 Target: Global/Mobile Users #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://www.techrepublic.com/article/news-microsoft-authenticator-vulnerability-android-ios-login-codes/

    Post summary

    Microsoft Authenticator CVE‑2026‑26123 can enable local interception of MFA codes on Android and iOS, but Microsoft has released a patch. No evidence of active exploitation or PoC existence is mentioned.

    0000075
    286 followersView on X
  • Snow@Snowddown
    General

    La folie encore … Ils ont réussi à trouver une faille dans Microsoft Authenticator .. Non mais des fois faut juste s’assoir et applaudir https://cve.org/CVERecord?id=CVE-2026-26123 https://t.co/cphapcKMr5

    Post summary

    The post briefly announces a flaw in Microsoft Authenticator and links to the CVE record, but provides no further information or actionable details.

    0000058
    67 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftauthenticator-android-
Appmicrosoftauthenticator-iphone_os-

Explore more