CyberICT

CVE-2026-41615

Microsoft · Published May 14, 2026

CVSS v3.1

CRITICAL
Patch availableGet patch

Description

Microsoft Authenticator Information Disclosure Vulnerability. Exposure of sensitive information to an unauthorized actor in Microsoft Authenticator allows an unauthorized attacker to disclose information over a network.

Affected Products

  • Microsoft Authenticator for Android
  • Microsoft Authenticator for IOS

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C