CVE-2026-33823Disclosure(microsoft / teams)

MEDIUMCVSS 6.5 · MEDIUM

Exploitation observed; activity peaked at 5 mentions and remains active

Immediate actions

  • Patch microsoft teams systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a network.

4.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-285

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • teams

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 18 mentions across 8 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 11 signals
  • Disclosure: 7 classified signals
  • General: 5 classified signals
  • Peaked 1d ago at 5 mentions (2026-06-10); latest day: 1
  • 18 total mentions across 8 days

Affected systems

Vendors
Products
teams

1 version affected across 1 product

Deep dive

Activity timeline18 mentions / 8d
01345Mentions · 2026-05-08: 3Mentions · 2026-05-09: 1Mentions · 2026-05-10: 3Mentions · 2026-05-12: 3Mentions · 2026-05-13: 1Mentions · 2026-05-18: 1Mentions · 2026-06-10: 5Mentions · 2026-06-11: 1Active Exploitation · 2026-06-11: 1Patch / Workaround · 2026-05-08: 2Patch / Workaround · 2026-05-09: 1Patch / Workaround · 2026-05-10: 1Patch / Workaround · 2026-05-12: 1Technical Details · 2026-05-08: 3Technical Details · 2026-05-10: 1Technical Details · 2026-05-12: 1Technical Details · 2026-05-18: 1Technical Details · 2026-06-10: 4Technical Details · 2026-06-11: 105-0805-0905-1005-1205-1305-1806-1006-11
Signal classification4 categories
Disclosure
738.9%
General
527.8%
Patch
527.8%
Active Exploitation
15.6%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-05-083
General1Patch2
2026-05-091
Patch1
2026-05-103
Disclosure1General1Patch1
2026-05-123
General2Patch1
2026-05-131
General1
2026-05-181
Disclosure1
2026-06-105
Disclosure5
2026-06-111
Active Exploitation1
Full discourse18 posts
  • Lyrie.ai@lyrie_ai
    General

    Unpopular opinion: The cybersecurity industry is selling you dashboards. CVE: CVE-2026-33823 CVSS: 9.6 (3.1) — CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N Severity: CRITICAL Status: Critical advisory

    Post summary

    The post merely enumerates a critical CVE with its CVSS score and severity but supplies no exploit, PoC, patch, or active‑usage information.

    1001055
    210 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 Critical - Microsoft Teams information disclosure (CVE-2026-33823) Improper authorization allows an authenticated attacker to access sensitive information over the network. 👉 No action required - fully mitigated by Microsoft

    Post summary

    Microsoft Teams encountered a critical information disclosure vulnerability (CVE-2026-33823), but Microsoft has fully mitigated it, so no action is required.

    0002079
    168 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    That confession cascaded. Microsoft Teams CVE-2026-33823 (CVSS 9.6) went from disclosure to active exploitation in under 24 hours. PAN-OS CVE-2026-0300 (CVSS 9.3) was under state-sponsored attack before patches existed. Ivanti EPMM CVE-2026-6973 weaponized in ransomware…

    Post summary

    The tweet asserts that Microsoft Teams CVE‑2026‑33823, PAN‑OS CVE‑2026‑0300, and Ivanti EPMM CVE‑2026‑6973 were all actively exploited soon after disclosure, with state‑sponsored attacks and ransomware weaponization.

    1000048
    266 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    On May 7, 2026, Microsoft assigned CVE-2026-33823 to an improper authorization vulnerability in the Teams Events Portal, a web-based interface used by enterprises to schedule, manage, and monitor live events, webinars, and large-scale meetings. The vulnerability permits…

    Post summary

    Microsoft has announced CVE‑2026‑33823, an improper authorization flaw affecting the Teams Events Portal, marking a new vulnerability disclosure.

    1000050
    258 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    The Collaboration Tool Paradox: Why CVE-2026-33823 in Teams Events Portal Matters to Every CISO Microsoft Teams Events Portal suffers from CVE-2026-33823, a CVSS 9.6 information disclosure vulnerability allowing authenticated attackers to access sensitive meeting…

    Post summary

    The post announces the new CVE‑2026‑33823 with its severity and impact, but offers no proof‑of‑concept, exploit code, or evidence of active use, and does not mention a fix or mitigation.

    1000048
    258 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Microsoft Teams Events Portal suffers from CVE-2026-33823, a CVSS 9.6 information disclosure vulnerability allowing authenticated attackers to access sensitive meeting metadata, attendee lists, and confidential presentation materials. Published May 7, 2026, this flaw…

    Post summary

    The post announces the discovery of a high‑severity information disclosure flaw (CVE‑2026‑33823) in Microsoft Teams Events Portal, specifying its impact on authenticated users.

    1000044
    258 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    The Collaboration Tool Paradox: CVE-2026-33823 Shows Why Teams Events Portal Is a Data Exfiltration Vector. Microsoft Teams Events Portal suffers from CVE-2026-33823, a CVSS 9.6 information disclosure vulnerability allowing authenticated attackers to access sensitive…

    Post summary

    The post announces a high‑severity information disclosure vulnerability (CVE‑2026‑33823) in Microsoft Teams Events Portal without providing PoC, exploit code, or patch details.

    1000057
    258 followersView on X
  • kawn@kawn2020
    General

    #windowsupdate #microsoft つづき ・CVE-2026-33109 9.9 Azure Managed Instance for Apache Cassandra ・CVE-2026-33821 7.7 Microsoft Dynamics 365 Customer Insights ・CVE-2026-33823 9.6 Microsoft Teams ・CVE-2026-33844 9  Azure Managed Instance for Apache Cassandra つづく…

    Post summary

    The tweet simply lists several upcoming CVE identifiers, their severity scores, and affected Microsoft products, without providing deeper technical or operational information.

    1000090
    85 followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-33823 — CVSS 9.6/10 ██████████ Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a network. Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/PdGbSQnTp1

    Post summary

    Microsoft Teams CVE-2026-33823 is a critical improper‑authorization flaw that allows information disclosure; a patch has been issued.

    1000096
    29 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    https://lyrie.ai/research/research/2026-05-09-cve-2026-33823-teams-events-data-leak #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The tweet references a research link about CVE‑2026‑33823, a Teams events data leak, but offers no explicit proof of concept, exploit details, active exploitation evidence, or mitigation information.

    0000035
    258 followersView on X
  • IntegSec@integ_sec
    Disclosure

    CVE-2026-33823: Microsoft Teams Events Portal Information Disclosure Bug - What It Means for Your Business and How to Respond https://hubs.li/Q04gYw5B0

    Post summary

    The article introduces CVE‑2026‑33823, an information‑disclosure vulnerability in Microsoft Teams Events Portal, and advises organizations on how to address the issue.

    0000048
    31 followersView on X
  • Vignesh_Pravin@VigneshVic23698
    Patch

    CVE-2026-33823: Critical Microsoft Teams Data Leak Fixed https://thecybrdef.com/cve-2026-33823-microsoft-teams-data-leak-vulnerability/ #Microsoftteams #Cyberupdates #Cybersecurity

    Post summary

    Article announces that Microsoft Teams CVE-2026-33823, a critical data leak vulnerability, has been fixed, confirming the vendor has released a patch but no exploit details are disclosed.

    0000067
    2 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-33823-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The provided text contains a link to an advisory for CVE-2026-33823 but does not disclose any specific details, PoC, exploits, or mitigation information.

    0000028
    210 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-33823 Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a network. https://www.cve.org/CVERecord?id=CVE-2026-33823 ----- Traducción: CVE-2026-33823 Autorización inapropiada en Microsoft Teams permite a un ata… http://infoflow.cloud`

    Post summary

    CVE-2026-33823 is a newly disclosed Microsoft Teams vulnerability that permits improper authorization and may allow an authorized attacker to disclose information over a network. No PoC, exploit tool, active exploitation evidence, or patch details are mentioned.

    0000029
    76 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-33823 Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a network. https://www.cve.org/CVERecord?id=CVE-2026-33823

    Post summary

    The text announces CVE‑2026‑33823 as an improper authorization in Microsoft Teams, but offers no actionable details or evidence of exploitation.

    00000248
    57.5K followersView on X
  • cybersecuritypath@cybrsecpath
    Patch

    CVE-2026-33823: Critical Microsoft Teams Data Leak Fixed https://thecybrdef.com/cve-2026-33823-microsoft-teams-data-leak-vulnerability/ #Microsoftteams #Cyberupdates #Cybersecurity

    Post summary

    The article announces that Microsoft Teams has been patched to fix a critical data leak vulnerability (CVE-2026-33823).

    0000046
    9 followersView on X
  • selva@SelvaKtm2
    Patch

    CVE-2026-33823: Critical Microsoft Teams Data Leak Fixed https://thecybrdef.com/cve-2026-33823-microsoft-teams-data-leak-vulnerability/ #Microsoftteams #Cyberupdates #Cybersecurity https://t.co/Wm8iD25PMZ

    Post summary

    The tweet announces that CVE-2026-33823, a critical data leak in Microsoft Teams, has been fixed. It references an external article for more information but provides no technical or exploit details.

    0000044
    5 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-33823 Information Disclosure in Microsoft Teams via Improper Authorizat... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33823 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The text announces CVE‑2026‑33823 as an information disclosure issue in Microsoft Teams, but lacks detail on proofs of concept, exploitation, mitigation, or active use.

    0000099
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftteams---

Explore more