CVE-2026-41615
Microsoft · Published May 14, 2026
9.6
CVSS v3.1
CRITICALPatch availableGet patch
Description
Microsoft Authenticator Information Disclosure Vulnerability. Exposure of sensitive information to an unauthorized actor in Microsoft Authenticator allows an unauthorized attacker to disclose information over a network.
Affected Products
- Microsoft Authenticator for Android
- Microsoft Authenticator for IOS
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C