The vendor has published a fix. Version details are below where the sources state them.
Steps
Written by AI from the record
Check whether your organization uses Microsoft Teams for business-critical communication (approvals, finance requests, onboarding) and confirm you are running current Microsoft Teams app versions.
Apply Microsoft’s security update for CVE-2026-62918 from the official MSRC update guide.
After updating, review Microsoft Teams message activity for unexpected impersonation-like behavior (messages that request payments, credential changes, or unusual instructions).
Ensure staff know to verify requests out-of-band (for example, call the person using a known number) before taking action on urgent or sensitive Teams messages.
Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing over a network.
In plain language
Written by AI from the record
CVE-2026-62918 lets an attacker impersonate others in Microsoft Teams and send fraudulent messages or commands without needing to log in, so businesses using Microsoft Teams should act urgently to apply Microsoft’s security update.
CVE-2026-62918 is an unauthenticated spoofing weakness (CWE-347) in Microsoft Teams where the system does not properly validate digital signatures, allowing forged network messages to impersonate legitimate identities.
If you're affected
Impersonation of staff or vendors
Fraudulent approvals or requests
Account and transaction compromise
Operational disruption
What is it
This vulnerability is like someone learning how to forge a “from me” signature so messages look like they came from a trusted coworker or service. In practice, an attacker could send convincing Teams messages that trigger fraud or harmful actions—without needing to log in themselves.
Who is affected
This matters to you if you use Microsoft Teams to communicate internally or externally, especially for decisions, payments, or urgent instructions. The risk is tied to whether an attacker can reach Microsoft Teams services over the network and send forged messages that bypass signature validation (no login or user interaction is required).
How urgent is it
RED: attackers have been reported in connection with this activity (PULSE notes sustained attention involving Lazarus group), and the weakness allows spoofing without credentials. Even without clear evidence of widespread public exploitation in the reporting, you should treat this as an active, high-impact impersonation risk and apply Microsoft’s fix immediately.
What to do — in detail
Confirm exposure
Inventory how your business uses Microsoft Teams (internal approvals, finance requests, vendor communications, incident handling).
Confirm that your endpoints (Windows/macOS/Linux desktops, mobile devices) are running current Microsoft Teams versions and that your organization is receiving Microsoft update channels/servicing as normal.
If your org uses centralized software management, route the update through your standard device update process and verify completion.
Validate after remediation
Monitor for impersonation-style activity: messages requesting payments, password/credential changes, gift cards, bank detail changes, or “quick action” instructions from unexpected senders.
Check for unusual patterns such as messages that create urgency, unusual attachment types, or inconsistent sender identity.
Temporary workaround if patching is delayed
Strengthen human verification for high-risk requests received via Teams: require a second confirmation path (phone call to a known number, or a separate ticketing workflow) before any payment/credential/action is performed.
Apply tighter internal controls for approvals (use a workflow that requires dual approval or confirmation outside Teams for finance-related changes).
What to monitor going forward
Ongoing alerts for spoofing-like behavior in Teams communication.
Reports from staff: “I got a message that looked like it came from X but didn’t,” and validate sender identity through trusted channels.
CISA due date: not specified in the provided findings (KEV is not listed).
Technical context
CVE-2026-62918 targets Microsoft Teams with a weakness classified as CWE-347 (Improper Verification of Cryptographic Signature). The key mechanism is improper validation of digital signatures, which enables forged network messages to impersonate legitimate identities without authentication and without user interaction (per findings: authentication required = none; user interaction = no).
Exploitation/exposure signals from provided sources: no dated KEV entry, no clear dated press claim, and no public exploit code noted; however, PULSE indicates sustained attention involving Lazarus group. The operational posture should therefore assume realistic adversary capability rather than relying on “no public exploit” as reassurance.
Attack vector: over the network to Microsoft Teams services (per findings).
KEV: not listed in CISA KEV (provided).
Patch: vendor remediation available via the MSRC update guide (provided link).
This is a general assessment based on public vulnerability data. It does not account for your specific infrastructure — when in doubt, consult a security specialist.