365 Copilot Chat
by Microsoft
CVEs (10)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-26137 | Cri | 0.64 | 9.9 | 0.01 | Mar 19, 2026 | Server-side request forgery (ssrf) in Microsoft Exchange allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2025-59286 | Cri | 0.60 | 9.3 | 0.01 | Oct 9, 2025 | Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2025-59272 | Cri | 0.60 | 9.3 | 0.01 | Oct 9, 2025 | Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to perform information disclosure locally. | ||
| CVE-2025-53787 | Hig | 0.53 | 8.2 | 0.01 | Aug 7, 2025 | Microsoft 365 Copilot BizChat Information Disclosure Vulnerability | ||
| CVE-2026-33111 | Hig | 0.49 | 7.5 | 0.01 | May 7, 2026 | Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-26164 | Hig | 0.49 | 7.5 | 0.01 | May 7, 2026 | Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-26129 | Hig | 0.49 | 7.5 | 0.01 | May 7, 2026 | Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-47644 | Med | 0.42 | 6.5 | 0.01 | Jun 4, 2026 | Improper neutralization of special elements in output used by a downstream component ('injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2025-53774 | Med | 0.42 | 6.5 | 0.01 | Aug 7, 2025 | Microsoft 365 Copilot BizChat Information Disclosure Vulnerability | ||
| CVE-2026-48561 | Cri | 0.00 | 9.6 | 0.01 | Jul 14, 2026 | Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to execute code over a network. |
- risk 0.64cvss 9.9epss 0.01
Server-side request forgery (ssrf) in Microsoft Exchange allows an authorized attacker to elevate privileges over a network.
- risk 0.60cvss 9.3epss 0.01
Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network.
- risk 0.60cvss 9.3epss 0.01
Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to perform information disclosure locally.
- risk 0.53cvss 8.2epss 0.01
Microsoft 365 Copilot BizChat Information Disclosure Vulnerability
- risk 0.49cvss 7.5epss 0.01
Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network.
- risk 0.49cvss 7.5epss 0.01
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.
- risk 0.49cvss 7.5epss 0.01
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.01
Improper neutralization of special elements in output used by a downstream component ('injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.01
Microsoft 365 Copilot BizChat Information Disclosure Vulnerability
- risk 0.00cvss 9.6epss 0.01
Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to execute code over a network.