Skip to main content

Vendor/product archive

microsoft / 365_copilot_chat CVEs

Beta · best-effort

7 CVEs tagged to microsoft / 365_copilot_chat3 Critical, 3 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2026-26164

Published May 7, 2026

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-26129

Published May 7, 2026

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-26137

Published Mar 19, 2026

Server-side request forgery (ssrf) in Microsoft Exchange allows an authorized attacker to elevate privileges over a network.

CVSS 9.9 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-59286

Published Oct 9, 2025

Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network.

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-59272

Published Oct 9, 2025

Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to perform information disclosure locally.

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-7 of 7 CVEsPage 1 of 1