VYPR

365 Copilot BizChat

by Microsoft

CVEs (9)

  • CVE-2026-24307CriJan 22, 2026
    risk 0.61cvss 9.3epss 0.01

    Improper validation of specified type of input in M365 Copilot allows an unauthorized attacker to disclose information over a network.

  • CVE-2025-32711CriJun 11, 2025
    risk 0.61cvss 9.3epss 0.08

    Ai command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.

  • CVE-2025-59286CriOct 9, 2025
    risk 0.60cvss 9.3epss 0.01

    Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network.

  • CVE-2025-59272CriOct 9, 2025
    risk 0.60cvss 9.3epss 0.01

    Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to perform information disclosure locally.

  • CVE-2025-59252CriOct 9, 2025
    risk 0.60cvss 9.3epss 0.01

    Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network.

  • CVE-2025-53787HigAug 7, 2025
    risk 0.53cvss 8.2epss 0.01

    Microsoft 365 Copilot BizChat Information Disclosure Vulnerability

  • CVE-2026-21521HigJan 22, 2026
    risk 0.48cvss 7.4epss 0.01

    Improper neutralization of escape, meta, or control sequences in Copilot allows an unauthorized attacker to disclose information over a network.

  • CVE-2025-53774MedAug 7, 2025
    risk 0.42cvss 6.5epss 0.01

    Microsoft 365 Copilot BizChat Information Disclosure Vulnerability

  • CVE-2026-24299MedMar 19, 2026
    risk 0.35cvss 5.3epss 0.01

    Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.