logo

Microsoft Authenticator could leak login codes—update your app now

ID: 1ff3f4eb-33c8-527e-82b2-0baa369783f5

STIX ID: report--1ff3f4eb-33c8-527e-82b2-0baa369783f5

Feed Name: Malwarebytes Blog

Threat Score
55/100

Date Published: 2026-03-12

Date Updated: 2026-04-28

...
...

**Executive summary:** A vulnerability (CVE-2026-26123) in Microsoft Authenticator for iOS and Android can leak one-time sign-in codes or sign-in deep links to a malicious app on the same device, potentially enabling account takeover and access to email, files, and cloud services; fixes are available and users should update the app or avoid installing apps that claim to handle authentication links until patched.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.