threat
engine
.sh
Back
·
··:··
Home
/
Product
/
microsoft authenticator
Product
microsoft authenticator
12 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2026-41615
< 6.2605.2973
Exposure of sensitive information to an unauthorized actor in Microsoft Authenticator allows an unauthorized attacker to disclose
9.6
CRITICAL
CVE-2026-33875
< 4.16.0
Gematik Authenticator securely authenticates users for login to digital health applications. Versions prior to 4.16.0 are vulnerab
9.3
CRITICAL
CVE-2026-33874
>= 4.12.0 and < 4.16.0
Gematik Authenticator securely authenticates users for login to digital health applications. Starting in version 4.12.0 and prior
7.8
HIGH
CVE-2026-26123
< 6.2511.7533
Cwe is not in rca categories in Microsoft Authenticator allows an unauthorized attacker to disclose information locally.
5.5
MEDIUM
CVE-2025-54154
>= 1.3.0 and < 1.3.1.1227
An improper authentication vulnerability has been reported to affect QNAP Authenticator. If an attacker gains physical access, the
6.8
MEDIUM
CVE-2024-45394
< 8.0.0
Authenticator is a browser extension that generates two-step verification codes. In versions 7.0.0 and below, encryption keys for
8.8
HIGH
CVE-2024-21390
< 6.2401.0617
Microsoft Authenticator Elevation of Privilege Vulnerability
7.1
HIGH
CVE-2023-27895
all versions
SAP Authenticator for Android - version 1.3.0, allows the screen to be captured, if an authorized attacker installs a malicious ap
6.1
MEDIUM
CVE-2022-3994
< 1.3.1
The Authenticator WordPress plugin before 1.3.1 does not prevent subscribers from updating a site's feed access token, which may d
4.3
MEDIUM
CVE-2022-35290
< 1.2.17
Under certain conditions SAP Authenticator for Android allows an attacker to access information which would otherwise be restricte
7.5
HIGH
CVE-2021-25266
<= 3.4
An insecure data storage vulnerability allows a physical attacker with root privileges to retrieve TOTP secret keys from unlocked
3.9
LOW
CVE-2012-6140
<= 0.91
pam_google_authenticator.c in the PAM module in Google Authenticator before 1.0 requires user-readable permissions for the secret
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin