CVE-2026-62918
Microsoft Teams Spoofing Vulnerability
Description
Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing over a network.
In plain language
AI Act nowCVE-2026-62918 lets an attacker impersonate others in Microsoft Teams and send fraudulent messages or commands without needing to log in, so businesses using Microsoft Teams should act urgently to apply Microsoft’s security update.
CVE-2026-62918 is an unauthenticated spoofing weakness (CWE-347) in Microsoft Teams where the system does not properly validate digital signatures, allowing forged network messages to impersonate legitimate identities.
What to do now
- Check whether your organization uses Microsoft Teams for business-critical communication (approvals, finance requests, onboarding) and confirm you are running current Microsoft Teams app versions.
- Apply Microsoft’s security update for CVE-2026-62918 from the official MSRC update guide.
- After updating, review Microsoft Teams message activity for unexpected impersonation-like behavior (messages that request payments, credential changes, or unusual instructions).
- Ensure staff know to verify requests out-of-band (for example, call the person using a known number) before taking action on urgent or sensitive Teams messages.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:NConfidentialityI:HIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
- Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Exploited Windows patch-tuesday
- Microsoft Patch Tuesday, August 2026 Security Update Reviewen-us·Qualys Security Blog· Exploited Windows patch-tuesday
- Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-daysen-us·BleepingComputer· Exploited Windows Lazarus group
- Microsoft Patch Tuesday August 2026 - SANS ISCen·SANS Internet Storm Center· Exploited Windows zero-day
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-62918 and every CVE in our database. Create a free account — no credit card required.
Create Free Account