SYS::ONLINE
Wasteland.
Briefs1769
Issues22
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-65667 2026-08-06

CVE-2026-65667: Critical Missing Authorization Flaw in Microsoft Teams Scores a Perfect 10.0

"Microsoft disclosed a missing authorization vulnerability in Microsoft Teams that lets an unauthenticated attacker elevate privileges over a network, rating it CVSS 10.0; the maximum possible score."

Microsoft disclosed a missing authorization vulnerability in Microsoft Teams that lets an unauthenticated attacker elevate privileges over a network, rating it CVSS 10.0; the maximum possible score.

What Is It

CVE-2026-65667 is a missing authorization weakness (CWE-862) in Microsoft Teams. Per Microsoft's description, the flaw "allows an unauthorized attacker to elevate privileges over a network." The CVE was published on 2026-08-06 and is currently in "Received" status in NVD, meaning analysis is still ongoing and the record's contents may change.

Microsoft tagged the record exclusively-hosted-service, indicating the affected component is a Microsoft-operated cloud service rather than software customers install and patch themselves.

Why It Matters

The CVSS 3.1 base score is 10.0 (CRITICAL), the highest value the scale allows. The vector, CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N, breaks down to a worst-case exploitability profile:

That yields an exploitability subscore of 3.9, the maximum. CISA's SSVC assessment reinforces the concern: exploitation is currently rated none (no known exploitation observed), but the flaw is marked automatable: yes with technical impact: total.

What's Vulnerable

Microsoft lists the affected product as Microsoft Teams with version status "-" (affected), and no CPE entries are enumerated in the NVD record. Because this is flagged as an exclusively hosted service, no specific client version boundaries are provided in the source data.

Patch Status

As of 2026-08-06, CVE-2026-65667 was not listed in the CISA Known Exploited Vulnerabilities catalog, so there is no KEV-confirmed active exploitation and no KEV-mandated remediation deadline at this time. That status can change without notice; readers should confirm against the live catalog, linked below, before relying on it.

The only vendor reference supplied is the MSRC update guide entry. Consistent with the exclusively-hosted-service tag, no customer-installable patch or required action is specified in the available data; administrators should consult the MSRC advisory directly for current guidance.

Sources