Skip to content

CVE-2026-41102

CVE

Threat entity extracted from intelligence sources

Frequency
2
occurrences
First Seen
June 3, 2026
Last Seen
June 3, 2026
API
Exploited in Wild
Ransomware Use
Public Exploits
Attack Vector

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

A coding error in Microsoft 365 Android applications allowed unauthorized apps to access user account tokens, leading to potential account takeovers. This vulnerability, known as FlagLeft, was due to a debug flag left enabled in production code across six major apps, including Word and Excel. Attack...

Public Exploits

Checking GitHub for proof-of-concept code…