Vulnerabilities (CVE)

Filtered by vendor Microsoft Subscribe
Filtered by product 365 Copilot
Total 5 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-26133 1 Microsoft 10 365 Copilot, Edge, Excel and 7 more 2026-04-09 N/A 7.1 HIGH
AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.
CVE-2026-24299 1 Microsoft 1 365 Copilot 2026-03-24 N/A 5.3 MEDIUM
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.
CVE-2025-32711 1 Microsoft 1 365 Copilot 2026-02-20 N/A 9.3 CRITICAL
Ai command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.
CVE-2026-24307 1 Microsoft 1 365 Copilot 2026-02-12 N/A 9.3 CRITICAL
Improper validation of specified type of input in M365 Copilot allows an unauthorized attacker to disclose information over a network.
CVE-2021-43905 1 Microsoft 1 365 Copilot 2025-06-11 6.8 MEDIUM 9.6 CRITICAL
Microsoft Office app Remote Code Execution Vulnerability