Microsoft Authenticator
- Known vulnerabilities
- 2
- Still open
- 0
- KEV open
- 0
- Max CVSS (historical)
- 9.6
Cumulative exposure
Low
Aggregates open CVEs (40%) + KEV (30%) + critical shared permissions (15%) + trackers (10%) + OS EOL (5%). Higher score = more exposed.
-
Open CVEs +0/+50
0 open CVEs, max CVSS 0.0, EPSS 0%
-
Active KEVs +0/+35
0 CISA KEVs still open
-
Permissions +0/+10
0 critical shared permission(s)
-
Trackers +0/+8
0 identification/profiling tracker(s)
-
EOL OS +0/+5
Installed OS is end-of-life
Known vulnerabilities (CVE)
Latest matched CVE: 2026
Test a different version
| CVE |
|---|
|
CVE-2026-41615
Fixed
CRITICAL 9.6
Network Fixed in: 6.8.47
|
|
CVE-2026-26123
Fixed
MEDIUM 5.5
Local Fixed in: 6.8.40
|
Security Score
Excellent
Composite: 50% open CVEs + 40% open KEVs + 10% vendor velocity.
-
Open CVEs 0/-50
0 CVEs
-
Open KEVs 0/-40
0 KEVs
-
Vendor 0/-10
100% fresh
Context
Context
Description
Use Microsoft Authenticator for easy, secure sign-ins for all your online accounts using multi-factor authentication, passwordless, or password autofill. You also have additional account management options for your Microsoft personal, work or school accounts. Getting started with multi-factor authentication Multi factor authentication (MFA)provides a second layer of security. When enabled, during login after entering your password, you’ll be asked for an additional way to prove it’s really you. Either approve the notification sent to the Microsoft Authenticator, or enter the one-time password (OTP) generated by the app. The OTP codes have a 30 second timer counting down. This timer is so you never have to use the same time-based one-time password (TOTP) twice and you don’t have to remember the number. The OTP doesn’t require you to be connected to a network, and it won’t drain your battery. You can add multiple accounts to your app, including non-Microsoft accounts like Facebook, Amazon, Dropbox, Google, LinkedIn, GitHub, and more. Getting started with passwordless Use your phone, not your password, to log into your Microsoft account.
Data collected and shared
Source: App Store · App Privacy · 6 data item(s) declared
Indicative classification based on data sensitivity. "Shared" = transmitted to third parties (publisher-declared).
Other apps by this publisher
Apps published by Microsoft Corporation
com.microsoft.emmxmsstore:9WZDNCRFJBBGcom.microsoft.crm.crmphonecom.microsoft.crm.crmphone.salesmsstore:9PMMSR1CGPWGcom.microsoft.LinkToWindowsFAQ
FAQ: Microsoft Authenticator
Does Microsoft Authenticator have known security vulnerabilities?
Microsoft Authenticator (com.microsoft.azureauthenticator) on iOS has 2 CVE referenced in NVD, 0 still open on the current version and 0 listed in the CISA KEV catalog. Absence of a CVE is not a security guarantee.
Is the current version of Microsoft Authenticator affected by any open CVE?
Version 6.8.52 of Microsoft Authenticator on iOS has no open CVE referenced in NVD. Absence of a CVE is not a security guarantee.
Is Microsoft Authenticator affected by an actively exploited vulnerability (CISA KEV)?
No CVE affecting Microsoft Authenticator (com.microsoft.azureauthenticator) is currently in the CISA KEV catalog.
What is the latest known version of Microsoft Authenticator?
The most recent version of Microsoft Authenticator (com.microsoft.azureauthenticator) tracked by Appaloosa Scout is 6.8.52, published by Microsoft Corporation.