microsoft 365_copilot CVE Vulnerabilities (10)

CVEs: 10 CPE versions: View versions table

Summary

This page lists publicly disclosed CVE vulnerabilities affecting microsoft 365_copilot (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.

Showing 110 of 10 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2026-42827 Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network. [email protected] 6.5 0.67% 2026-05-22 2026-05-27
CVE-2026-41090 Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network. [email protected] 9.3 0.56% 2026-05-22 2026-05-27
CVE-2026-41614 Improper access control in M365 Copilot for Desktop allows an unauthorized attacker to perform spoofing locally. [email protected] 6.2 0.36% 2026-05-12 2026-05-14
CVE-2026-41100 Improper access control in M365 Copilot allows an authorized attacker to perform spoofing locally. [email protected] 4.4 0.25% 2026-05-12 2026-05-16
CVE-2026-33102 Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network. [email protected] 9.3 0.39% 2026-04-23 2026-04-29
CVE-2026-24299 Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network. [email protected] 5.3 0.63% 2026-03-19 2026-03-24
CVE-2026-26133 AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network. [email protected] 7.1 0.43% 2026-03-16 2026-04-09
CVE-2026-24307 Improper validation of specified type of input in M365 Copilot allows an unauthorized attacker to disclose information over a network. [email protected] 9.3 0.81% 2026-01-22 2026-02-12
CVE-2025-32711 Ai command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network. [email protected] 9.3 4.63% 2025-06-11 2026-02-20
CVE-2021-43905 Microsoft Office app Remote Code Execution Vulnerability [email protected] 9.6 2.82% 2021-12-15 2025-06-11
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence