← Back

Copilot

copilot

Vendor: Microsoft • 4 CVEs

CVEs (4)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
1Copilot
Jul 22, 2026
Jul 14, 2026
N/A· v4
7.1 HIGH· v3
N/A· v2
Improper neutralization of special elements used in a command ('command injection') in Outlook Copilot allows an authorized attacker to perform tampering over a network.
1Microsoft
1Copilot
Jul 23, 2026
Jun 4, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an authorized attacker to execute code over a network.
1Microsoft
1Copilot
Jul 23, 2026
Jun 4, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.
1Microsoft
1Copilot
Jun 17, 2026
Mar 19, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.