CVE-2026-42835 Microsoft Teams for Android Information Disclosure Vulnerability
Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-42835 Microsoft US