CVE-2026-41615Patch(microsoft / authenticator)

LOWCVSS 7.4 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch microsoft authenticator systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Exposure of sensitive information to an unauthorized actor in Microsoft Authenticator allows an unauthorized attacker to disclose information over a network.

2.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • authenticator

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 17 mentions across 10 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 8 signals
  • Technical details provided in 12 signals
  • Disclosure: 6 classified signals
  • General: 4 classified signals
  • Peaked 4d ago at 4 mentions (2026-05-20); latest day: 1
  • 17 total mentions across 10 days

Affected systems

Vendors
Products
authenticator

Deep dive

Activity timeline17 mentions / 10d
01234Mentions · 2026-05-14: 3Mentions · 2026-05-15: 3Mentions · 2026-05-17: 1Mentions · 2026-05-18: 1Mentions · 2026-05-19: 1Mentions · 2026-05-20: 4Mentions · 2026-05-21: 1Mentions · 2026-05-25: 1Mentions · 2026-06-03: 1Mentions · 2026-06-14: 1PoC Mentioned / Linked · 2026-06-03: 1Patch / Workaround · 2026-05-14: 3Patch / Workaround · 2026-05-15: 2Patch / Workaround · 2026-05-18: 1Patch / Workaround · 2026-05-20: 1Patch / Workaround · 2026-05-21: 1Technical Details · 2026-05-14: 3Technical Details · 2026-05-15: 3Technical Details · 2026-05-18: 1Technical Details · 2026-05-20: 2Technical Details · 2026-05-21: 1Technical Details · 2026-06-03: 1Technical Details · 2026-06-14: 105-1405-1505-1705-1805-1905-2005-2105-2506-0306-14
Signal classification3 categories
Patch
741.2%
Disclosure
635.3%
General
423.5%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-05-143
Disclosure1Patch2
2026-05-153
Disclosure1Patch2
2026-05-171
Disclosure1
2026-05-181
Patch1
2026-05-191
General1
2026-05-204
Disclosure1General2Patch1
2026-05-211
Patch1
2026-05-251
General1
2026-06-031
Disclosure1
2026-06-141
Disclosure1
Full discourse17 posts
  • ヤスムラ@スタートアップの情シス@yasuym1
    Patch

    Microsoft Authenticatorでクリティカルの脆弱性(CVE-2026-41615 / CVSS 9.6 Critical) 利用者は速やかに最新版に更新して従業員に見に覚えのない承認通知を無視するよう案内しましょう。 https://www.security-next.com/184490

    Post summary

    The advisory announces a critical vulnerability (CVE-2026-41615, CVSS 9.6) in Microsoft Authenticator and urges users to update to the latest version and ignore unfamiliar approval notifications.

    1191713612.4K
    2.4K followersView on X
  • mattn@mattn_jp
    General

    Microsoft Authenticator の CVE 出てる。 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41615

    Post summary

    The tweet announces a Microsoft Authenticator CVE (CVE‑2026‑41615) and provides a link to MSRC, but offers no technical, exploit, or patch details.

    1223582216.6K
    48.2K followersView on X
  • Carlos Fynn@fynn_JourX
    Disclosure

    Legacy exposure keeps paying off for attackers. CVE-2026-41615: Microsoft Authenticator Token Theft Risk CVE-2026-41615 in Microsoft Authenticator can expose work-account tokens after a malicious… 🔗 Read → https://invaders.ie/resources/blog/vulnerability/cve-2026-41615-microsoft-authenticator-token-theft-risk

    Post summary

    The post announces a new Microsoft Authenticator vulnerability (CVE-2026-41615) that can expose work-account tokens, but no exploit, patch, or PoC is referenced.

    02030213
    85 followersView on X
  • kawn@kawn2020
    Patch

    #securityupdate #microsoft #定例外 2026. 5.14 Microsoft Authenticator の情報漏えいの脆弱性 CVE-2026-41615 Security Vulnerability リリース日: - マイクロソフト https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41615

    Post summary

    Microsoft has released a security update for CVE-2026-41615, addressing an information leakage vulnerability in Microsoft Authenticator, with details linked to the MSRC update guide.

    10110254
    85 followersView on X
  • Sami Laiho@samilaiho
    Patch

    Microsoft Authenticator Information Disclosure Vulnerability URL: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41615 Classification: Critical, Solution: Official Fix, Exploit Maturity: Unproven, CVSSv3.1: 9.6

    Post summary

    Microsoft released an official fix for the critical information disclosure vulnerability CVE-2026-41615, rated 9.6 CVSSv3.1.

    00030506
    30.6K followersView on X
  • kawn@kawn2020
    General

    #securityupdate #microsoft #定例外 CVE-2026-41615 影響: 情報漏えい 最大深刻度: 緊急 CVSS:3.1 9.6 / 8.3 悪用可能性 ・一般に公開: No ・悪用: No ・Exploitability assessment: 悪用される可能性は低い https://x.com/kawn2020/status/2056988766775193906

    Post summary

    The tweet reports CVE‑2026‑41615 as an information‑disclosure flaw with a high CVSS score, noting no public exploitation or PoC, and provides basic technical details without referencing patches or active attacks.

    10010110
    85 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨Critical - Microsoft Authenticator Sensitive Information Disclosure (CVE-2026-41615) Exposure of sensitive information to an unauthorized actor in Microsoft Authenticator allows an unauthorized attacker to disclose information over a network. The vulnerability can expose a sign-in access token for a user’s work account, potentially allowing access to organizational data and services. This has a critical impact on work/school accounts (CVSS 9.6). 👉Affected: Microsoft Authenticator

    Post summary

    The post announces CVE-2026-41615, a critical sensitive information disclosure in Microsoft Authenticator that can expose user sign‑in tokens with a CVSS score of 9.6, without mentioning any patch, PoC, or active exploitation.

    00011224
    196 followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-41615 — CVSS 9.6/10 ██████████ Exposure of sensitive information to an unauthorized actor in Microsoft Authenticator allows an unauthorized attacker... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/foVspioMYO

    Post summary

    The tweet announces the critical Microsoft Authenticator vulnerability CVE‑2026‑41615 with a high CVSS score and urges immediate patching, without providing PoC or exploit details.

    10010244
    34 followersView on X
  • Meridian Group@MeridianEU
    Disclosure

    CVE-2026-41615 (CVSS 9.6) in Microsoft Authenticator enables disclosure of authentication tokens via social engineering. Successful exploitation allows threat actors to bypass #MFA and gain unauthorized access to enterprise resources. https://t.co/SlemFY4U1R

    Post summary

    The tweet announces that CVE-2026-41615 in Microsoft Authenticator allows attackers to disclose authentication tokens through social engineering, enabling bypass of MFA and access to enterprise resources.

    0000153
    60 followersView on X
  • Israel@f1tym1
    Disclosure

    CVE-2026-41615 | Microsoft Authenticator prior 6.2605.2973 on Android/iOS information disclosure (WID-SEC-2026-1537) https://ift.tt/JuvId24 A vulnerability has been found in Microsoft Authenticator on Android/iOS and classified as problematic. This impacts an unknown function.…

    Post summary

    The post announces CVE-2026-41615, an information‑disclosure flaw in Microsoft Authenticator for Android/iOS, but provides no PoC, exploit details, patch information, or technical specifics.

    01000114
    974 followersView on X
  • Wilhelm Klenner@WilhelmKlenner
    Disclosure

    Eine neue Sicherheitslücke im Microsoft Authenticator gibt Angreifern kompletten Zugriff auf dein Konto und das ganz ohne Exploit! Mit einem CVSS-Score von 9.6, ist diese Sicherheitslücke CVE-2026-41615 offiziell als kritisch eingestuft. https://www.purple-tec.at/authenticator-zugang-ohne-exploit/ https://t.co/ZeCnzNNJ1r

    Post summary

    A newly disclosed critical vulnerability (CVE‑2026‑41615) in Microsoft Authenticator is announced, with a linked article suggesting attackers can fully compromise accounts without a traditional exploit, but no exploit code or active attacks are mentioned.

    0000047
    14 followersView on X
  • Master2Manage Pty Ltd@Master2Manage
    Patch

    👩🏿‍💻🚨 That "Approve" button just became a backdoor. CVE-2026-41615: Attackers steal your session token when you tap "Approve". Then they own your tenant. Check your Authenticator version. NOW. Android: 6.2605.2973 iOS: 6.8.47 #MFA #TokenTheft More 👇 https://www.linkedin.com/posts/master2manage-pty-ltd-australia_mfa-tokentheft-microsoftauthenticator-activity-7463336575234625536-IEfu?utm_source=share&utm_medium=member_ios&rcm=ACoAAAIz3dAB3Vbe3UhtnPuGIH2tBg5TjxlkBT8

    Post summary

    CVE‑2026‑41615 creates a backdoor through the Approve button that steals session tokens; the post urges users to upgrade Microsoft Authenticator to the latest Android (6.2605.2973) or iOS (6.8.47) releases.

    00000110
    122 followersView on X
  • Lucas@lucasverdan
    General

    🛑 CVE-2026-41615: Microsoft Authenticator Token Theft Risk CVE-2026-41615 in Microsoft Authenticator can expose work-account tokens after a malicious… 🔗 Details → https://invaders.ie/resources/blog/vulnerability/cve-2026-41615-microsoft-authenticator-token-theft-risk

    Post summary

    A brief tweet announcing Microsoft Authenticator token theft risk associated with CVE‑2026‑41615, linking to a blog post for more details.

    0000093
    308 followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Microsoft ❗ CVE-2026-42897 ❗ CVE-2026-41615 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-microsoft-9/ https://t.co/D99tEQdWTa

    Post summary

    The post simply lists two Microsoft CVEs and directs readers to a CERT page for additional information, without specifying technical details, proofs, or exploits.

    00000127
    6.7K followersView on X
  • Mails Nielsen@MailsNielsen
    Patch

    🚨 CVE-2026-41615 (CVSS 9.6) - Microsoft Authenticator leaks sign-in tokens via malicious requests. Patch now: Android 6.2605.2973 / iOS 6.8.47 #infosec

    Post summary

    The tweet announces CVE‑2026‑41615, a high‑severity token leakage flaw in Microsoft Authenticator, and provides immediate patch versions for Android and iOS, urging users to update.

    00000147
    133 followersView on X
  • ProjetoLabo@ProjetoLabo
    Patch

    Microsoft Authenticator, usado por milhões pra 2FA, tem falha crítica. CVE-2026-41615, nota 9.6. Atacante remoto consegue vazar dados sensíveis do app sem precisar de senha. A vítima só precisa clicar em algo. Microsoft já lançou patch. Se usa Authenticator, atualiza agora. #Microsoft

    Post summary

    CVE‑2026‑41615 is a critical flaw in Microsoft Authenticator allowing data exfiltration with a click; Microsoft has issued a patch that users should apply immediately.

    00000183
    166 followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    🚨 CRITICAL — CVE-2026-41615 Exposure of sensitive information to an unauthorized actor in Microsoft Authenticator allows an unauthorized attacker t… CVSS 9.6 🔴 No patch yet Full analysis → https://sec.kaitan.id/cves/CVE-2026-41615 #Microsoft #CyberSecurity #InfoSec

    Post summary

    The tweet announces CVE-2026-41615, a critical Microsoft Authenticator info‑disclosure bug with a CVSS of 9.6 and no patch released yet, pointing to a full analysis link.

    00000116
    90 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftauthenticator-android-
Appmicrosoftauthenticator-iphone_os-

Explore more