VYPR

M365 Copilot

by Microsoft

CVEs (13)

  • CVE-2026-54130CriJun 18, 2026
    risk 0.64cvss 9.8epss 0.01

    Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-24307CriJan 22, 2026
    risk 0.61cvss 9.3epss 0.01

    Improper validation of specified type of input in M365 Copilot allows an unauthorized attacker to disclose information over a network.

  • CVE-2025-32711CriJun 11, 2025
    risk 0.61cvss 9.3epss 0.08

    Ai command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-33102CriApr 23, 2026
    risk 0.60cvss 9.3epss 0.00

    Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-26164HigMay 7, 2026
    risk 0.49cvss 7.5epss 0.01

    Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-26129HigMay 7, 2026
    risk 0.49cvss 7.5epss 0.01

    Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-42893HigMay 12, 2026
    risk 0.48cvss 7.4epss 0.00

    Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to perform tampering over a network.

  • CVE-2026-26133HigMar 16, 2026
    risk 0.46cvss 7.1epss 0.00

    AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-42827MedMay 22, 2026
    risk 0.42cvss 6.5epss 0.01

    Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-24299MedMar 19, 2026
    risk 0.35cvss 5.3epss 0.01

    Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-41100MedMay 12, 2026
    risk 0.29cvss 4.4epss 0.00

    Improper access control in M365 Copilot allows an authorized attacker to perform spoofing locally.

  • CVE-2026-50517CriJul 24, 2026
    risk 0.00cvss 9.9epss 0.01

    Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.

  • CVE-2026-41106CriJul 2, 2026
    risk 0.00cvss 9.3epss 0.01

    Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.