VulnSea

365_copilot vulnerabilities

CVEs whose affected-version data names the 365_copilot package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

7 CVEsRSS

CVE-2026-85887High· 7.7
4d ago

Incorrect permission assignment for critical resource in M365 Copilot allows an authorized attacker to disclose information over a network.

Incorrect permission assignment for critical resource in M365 Copilot allows an authorized attacker to disclose information over a network.

TwilightMicrosoft · Microsoft 365 CopilotEPSS 0.48%via NVD
CVE-2026-85885Critical· 9.9
5d ago

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized attacker to elevate privileges over a network.

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized attacker to elevate privileges over a network.

MidnightMicrosoft · Microsoft 365 CopilotEPSS 0.53%via NVD
CVE-2026-50517Critical· 9.9
2mo ago

Microsoft M365 Copilot Remote Code Execution Vulnerability

Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.

MidnightMicrosoft · Microsoft 365 CopilotEPSS 1.3%via CVEORG
CVE-2026-48561Critical· 9.6
2mo ago

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to execute code over a network.

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to execute code over a network.

Midnightmicrosoft · 365_copilotEPSS 0.86%via NVD
CVE-2026-41106Critical· 9.3
2mo ago

Microsoft 365 Copilot Elevation of Privilege Vulnerability

Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.

MidnightMicrosoft · Microsoft 365 CopilotEPSS 0.72%via CVEORG
CVE-2026-42827Medium· 6.5
4mo ago

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.

Sunlitmicrosoft · 365_copilotEPSS 0.50%via NVD
CVE-2026-41090Critical· 9.3
4mo ago

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network.

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network.

Midnightmicrosoft · 365_copilotEPSS 0.42%via NVD
365_copilot vulnerabilities (CVEs) · VulnSea