CVE-2026-80097: Microsoft Authenticator flaw rated 8.6
NVD describes CVE-2026-80097 as improper authentication in Microsoft Authenticator (CWE-287) that lets an attacker elevate privileges locally. The CVSS base score is 8.6, the record was published on 8 September 2026, and Microsoft's update guide is the vendor reference.
- CVSS base score is 8.6, weakness type CWE-287
- Local attack: privilege escalation, not remote takeover
- Affects passwordless credentials and account metadata in the app
- Recommended: platform lock, number matching, fewer accounts per device
Read next
Security