CVE-2026-41100 is a vulnerability tracked across 1 threat cluster and 2 intelligence report mentions on ThreatCluster. First observed June 3, 2026; most recent activity June 3, 2026.
A coding error in Microsoft 365 Android applications allowed unauthorized apps to access user account tokens, leading to potential account takeovers. This vulnerability, known as FlagLeft, was due to a debug flag left…