CVE-2026-50517
- EPSS 1.25%
- Veröffentlicht 24.07.2026 00:01:11
- Zuletzt bearbeitet 29.07.2026 14:19:20
Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.
CVE-2026-58617
- EPSS 0.74%
- Veröffentlicht 14.07.2026 17:10:11
- Zuletzt bearbeitet 16.07.2026 20:09:34
Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-50387
- EPSS 1.92%
- Veröffentlicht 14.07.2026 17:07:08
- Zuletzt bearbeitet 22.07.2026 16:17:49
Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges locally.
CVE-2026-48561
- EPSS 0.76%
- Veröffentlicht 14.07.2026 17:04:12
- Zuletzt bearbeitet 26.07.2026 18:17:38
Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to execute code over a network.
CVE-2026-41106
- EPSS 0.53%
- Veröffentlicht 02.07.2026 22:18:57
- Zuletzt bearbeitet 07.07.2026 14:24:12
Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-47645
- EPSS 0.76%
- Veröffentlicht 19.06.2026 20:29:42
- Zuletzt bearbeitet 26.06.2026 21:42:08
Url redirection to untrusted site ('open redirect') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-42895
- EPSS 0.4%
- Veröffentlicht 19.06.2026 20:27:46
- Zuletzt bearbeitet 26.06.2026 21:40:08
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network.
CVE-2026-54130
- EPSS 0.58%
- Veröffentlicht 18.06.2026 21:42:39
- Zuletzt bearbeitet 25.06.2026 18:59:48
Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose information over a network.
CVE-2026-45474
- EPSS 0.36%
- Veröffentlicht 09.06.2026 17:17:21
- Zuletzt bearbeitet 23.07.2026 08:10:00
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-45472
- EPSS 0.36%
- Veröffentlicht 09.06.2026 17:17:21
- Zuletzt bearbeitet 23.07.2026 08:10:00
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.