Vulnerabilities (CVE)

Filtered by vendor Microsoft Subscribe
Filtered by product 365 Copilot
Total 52 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-50517 1 Microsoft 1 365 Copilot 2026-07-29 N/A 9.9 CRITICAL
Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.
CVE-2026-48561 1 Microsoft 1 365 Copilot 2026-07-26 N/A 9.6 CRITICAL
Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to execute code over a network.
CVE-2026-42827 1 Microsoft 1 365 Copilot 2026-07-23 N/A 6.5 MEDIUM
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.
CVE-2026-41090 1 Microsoft 1 365 Copilot 2026-07-23 N/A 9.3 CRITICAL
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network.
CVE-2026-45460 1 Microsoft 6 365 Apps, 365 Copilot, Microsoft 365 and 3 more 2026-07-23 N/A 4.7 MEDIUM
Buffer over-read in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-45461 1 Microsoft 7 365 Apps, 365 Copilot, Microsoft 365 and 4 more 2026-07-23 N/A 8.4 HIGH
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-45463 1 Microsoft 7 365 Apps, 365 Copilot, Microsoft 365 and 4 more 2026-07-23 N/A 8.4 HIGH
Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-45474 1 Microsoft 7 365 Apps, 365 Copilot, Microsoft 365 and 4 more 2026-07-23 N/A 8.4 HIGH
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-45472 1 Microsoft 7 365 Apps, 365 Copilot, Microsoft 365 and 4 more 2026-07-23 N/A 8.4 HIGH
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-50387 1 Microsoft 16 365 Copilot, Microsoft 365, Office 2021 and 13 more 2026-07-22 N/A 7.8 HIGH
Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges locally.
CVE-2026-58617 1 Microsoft 1 365 Copilot 2026-07-16 N/A 8.1 HIGH
Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-41106 1 Microsoft 1 365 Copilot 2026-07-07 N/A 9.3 CRITICAL
Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-47645 1 Microsoft 1 365 Copilot 2026-06-26 N/A 8.8 HIGH
Url redirection to untrusted site ('open redirect') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-42895 1 Microsoft 1 365 Copilot 2026-06-26 N/A 6.5 MEDIUM
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network.
CVE-2026-54130 1 Microsoft 1 365 Copilot 2026-06-25 N/A 9.8 CRITICAL
Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose information over a network.
CVE-2026-42831 1 Microsoft 3 365 Copilot, Office, Office Long Term Servicing Channel 2026-06-17 N/A 7.8 HIGH
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-41614 1 Microsoft 1 365 Copilot 2026-06-17 N/A 6.2 MEDIUM
Improper access control in M365 Copilot for Desktop allows an unauthorized attacker to perform spoofing locally.
CVE-2026-41100 1 Microsoft 1 365 Copilot 2026-06-17 N/A 4.4 MEDIUM
Improper access control in M365 Copilot allows an authorized attacker to perform spoofing locally.
CVE-2026-40363 1 Microsoft 4 365 Apps, 365 Copilot, Office and 1 more 2026-06-17 N/A 8.4 HIGH
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-33102 1 Microsoft 1 365 Copilot 2026-06-17 N/A 9.3 CRITICAL
Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.