VYPR

365 Copilot Chat

by Microsoft

CVEs (10)

  • CVE-2026-26137CriMar 19, 2026
    risk 0.64cvss 9.9epss 0.01

    Server-side request forgery (ssrf) in Microsoft Exchange allows an authorized attacker to elevate privileges over a network.

  • CVE-2025-59286CriOct 9, 2025
    risk 0.60cvss 9.3epss 0.01

    Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network.

  • CVE-2025-59272CriOct 9, 2025
    risk 0.60cvss 9.3epss 0.01

    Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to perform information disclosure locally.

  • CVE-2025-53787HigAug 7, 2025
    risk 0.53cvss 8.2epss 0.01

    Microsoft 365 Copilot BizChat Information Disclosure Vulnerability

  • CVE-2026-33111HigMay 7, 2026
    risk 0.49cvss 7.5epss 0.01

    Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-26164HigMay 7, 2026
    risk 0.49cvss 7.5epss 0.01

    Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-26129HigMay 7, 2026
    risk 0.49cvss 7.5epss 0.01

    Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-47644MedJun 4, 2026
    risk 0.42cvss 6.5epss 0.01

    Improper neutralization of special elements in output used by a downstream component ('injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network.

  • CVE-2025-53774MedAug 7, 2025
    risk 0.42cvss 6.5epss 0.01

    Microsoft 365 Copilot BizChat Information Disclosure Vulnerability

  • CVE-2026-48561CriJul 14, 2026
    risk 0.00cvss 9.6epss 0.01

    Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to execute code over a network.