CVE-2026-42893
Published May 12, 2026Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to perform tampering over a network.
- evidence mentions
- 2
- Buzz score
- 17.5
Vendor/product archive
120 CVEs tagged to microsoft / outlook — 10 Critical, 53 High, 57 Medium, 0 Low, 0 Unrated.
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to perform tampering over a network.
AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.
Exposure of sensitive information to an unauthorized actor in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
Improper input validation in Microsoft Office Outlook allows an authorized attacker to execute code locally.
Exposure of sensitive information to an unauthorized actor in Outlook for Android allows an unauthorized attacker to disclose information over a network.
Microsoft Outlook Spoofing Vulnerability
Microsoft Outlook Remote Code Execution Vulnerability
Microsoft Outlook Remote Code Execution Vulnerability
A library injection vulnerability exists in Microsoft Outlook 16.83.3 for macOS. A specially crafted library can leverage Outlook's access privileges, leading to a permission bypa…
Outlook for Android Elevation of Privilege Vulnerability
Microsoft Outlook for iOS Information Disclosure Vulnerability
Microsoft Outlook Remote Code Execution Vulnerability
Microsoft Outlook Spoofing Vulnerability
Microsoft Outlook Remote Code Execution Vulnerability
Outlook for Windows Spoofing Vulnerability
Outlook for Android Information Disclosure Vulnerability
Microsoft Outlook Remote Code Execution Vulnerability
Microsoft Outlook Information Disclosure Vulnerability
Microsoft Outlook Spoofing Vulnerability
Microsoft Outlook Security Feature Bypass Vulnerability
Microsoft Outlook Remote Code Execution Vulnerability
Microsoft Outlook Denial of Service Vulnerability
Microsoft Outlook Elevation of Privilege Vulnerability
Outlook for Android Elevation of Privilege Vulnerability