Home/Product/microsoft authenticator
Product

microsoft authenticator

12 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-41615
< 6.2605.2973
Exposure of sensitive information to an unauthorized actor in Microsoft Authenticator allows an unauthorized attacker to disclose
9.6CRITICAL
CVE-2026-33875
< 4.16.0
Gematik Authenticator securely authenticates users for login to digital health applications. Versions prior to 4.16.0 are vulnerab
9.3CRITICAL
CVE-2026-33874
>= 4.12.0 and < 4.16.0
Gematik Authenticator securely authenticates users for login to digital health applications. Starting in version 4.12.0 and prior
7.8HIGH
CVE-2026-26123
< 6.2511.7533
Cwe is not in rca categories in Microsoft Authenticator allows an unauthorized attacker to disclose information locally.
5.5MEDIUM
CVE-2025-54154
>= 1.3.0 and < 1.3.1.1227
An improper authentication vulnerability has been reported to affect QNAP Authenticator. If an attacker gains physical access, the
6.8MEDIUM
CVE-2024-45394
< 8.0.0
Authenticator is a browser extension that generates two-step verification codes. In versions 7.0.0 and below, encryption keys for
8.8HIGH
CVE-2024-21390
< 6.2401.0617
Microsoft Authenticator Elevation of Privilege Vulnerability
7.1HIGH
CVE-2023-27895
all versions
SAP Authenticator for Android - version 1.3.0, allows the screen to be captured, if an authorized attacker installs a malicious ap
6.1MEDIUM
CVE-2022-3994
< 1.3.1
The Authenticator WordPress plugin before 1.3.1 does not prevent subscribers from updating a site's feed access token, which may d
4.3MEDIUM
CVE-2022-35290
< 1.2.17
Under certain conditions SAP Authenticator for Android allows an attacker to access information which would otherwise be restricte
7.5HIGH
CVE-2021-25266
<= 3.4
An insecure data storage vulnerability allows a physical attacker with root privileges to retrieve TOTP secret keys from unlocked
3.9LOW
CVE-2012-6140
<= 0.91
pam_google_authenticator.c in the PAM module in Google Authenticator before 1.0 requires user-readable permissions for the secret
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin