Skip to main content

Vendor/product archive

microsoft / 365_copilot CVEs

Beta · best-effort

51 CVEs tagged to microsoft / 365_copilot10 Critical, 32 High, 9 Medium, 0 Low, 0 Unrated.

CVE-2026-58617

Published Jul 14, 2026

Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network.

CVSS 8.1 · High
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort

CVE-2026-48561

Published Jul 14, 2026

Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to execute code over a network.

CVSS 9.6 · Critical
evidence mentions
10
Buzz score
44.0
Vendor/product tagsBeta · best-effort

CVE-2026-41106

Published Jul 2, 2026

Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.

CVSS 9.3 · Critical
evidence mentions
3
Buzz score
21.9
Vendor/product tagsBeta · best-effort

CVE-2026-47645

Published Jun 19, 2026

Url redirection to untrusted site ('open redirect') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to elevate privileges over a network.

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-42895

Published Jun 19, 2026

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network.

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-54130

Published Jun 18, 2026

Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose information over a network.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-42827

Published May 22, 2026

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-41090

Published May 22, 2026

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network.

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-41614

Published May 12, 2026

Improper access control in M365 Copilot for Desktop allows an unauthorized attacker to perform spoofing locally.

CVSS 6.2 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-41100

Published May 12, 2026

Improper access control in M365 Copilot allows an authorized attacker to perform spoofing locally.

CVSS 4.4 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-33102

Published Apr 23, 2026

Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-24299

Published Mar 19, 2026

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2026-26134

Published Mar 10, 2026

Integer overflow or wraparound in Microsoft Office allows an authorized attacker to elevate privileges locally.

CVSS 7.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort
Showing 1-25 of 51 CVEsPage 1 of 3