Improper Authentication in Microsoft Authenticator for Android - CVE-2026-80097
Published: September 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to improper authentication in Microsoft Authenticator. A remote attacker can trick a victim to install and run a malicious application, complete an authentication flow in Microsoft Authenticator and gain access to the target system.