CVE-2026-85887
- EPSS 0.48%
- Veröffentlicht 17.09.2026 23:04:48
- Zuletzt bearbeitet 28.09.2026 18:37:31
Incorrect permission assignment for critical resource in M365 Copilot allows an authorized attacker to disclose information over a network.
CVE-2026-78501
- EPSS 0.49%
- Veröffentlicht 17.09.2026 22:55:56
- Zuletzt bearbeitet 07.10.2026 14:11:24
Improper neutralization of special elements used in a command ('command injection') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to disclose information over a network.
CVE-2026-85885
- EPSS 0.53%
- Veröffentlicht 17.09.2026 22:55:55
- Zuletzt bearbeitet 25.09.2026 20:00:26
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized attacker to elevate privileges over a network.
CVE-2026-50517
- EPSS 1.25%
- Veröffentlicht 24.07.2026 00:01:11
- Zuletzt bearbeitet 29.07.2026 14:19:20
Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.
CVE-2026-58617
- EPSS 0.74%
- Veröffentlicht 14.07.2026 17:10:11
- Zuletzt bearbeitet 16.07.2026 20:09:34
Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-50387
- EPSS 1.92%
- Veröffentlicht 14.07.2026 17:07:08
- Zuletzt bearbeitet 22.07.2026 16:17:49
Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges locally.
CVE-2026-48561
- EPSS 0.76%
- Veröffentlicht 14.07.2026 17:04:12
- Zuletzt bearbeitet 26.07.2026 18:17:38
Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to execute code over a network.
CVE-2026-41106
- EPSS 0.53%
- Veröffentlicht 02.07.2026 22:18:57
- Zuletzt bearbeitet 07.07.2026 14:24:12
Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-47645
- EPSS 0.76%
- Veröffentlicht 19.06.2026 20:29:42
- Zuletzt bearbeitet 26.06.2026 21:42:08
Url redirection to untrusted site ('open redirect') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-42895
- EPSS 0.4%
- Veröffentlicht 19.06.2026 20:27:46
- Zuletzt bearbeitet 26.06.2026 21:40:08
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network.