CyberRota Analysis
AI-GeneratedMicrosoft Edge's Copilot Chat is vulnerable to a critical command injection flaw that enables unauthorized attackers to execute arbitrary code remotely. This vulnerability poses a significant risk to users, particularly organizations relying on Microsoft Edge for secure communications. IT security teams should prioritize patching this issue to mitigate potential exploitation.
CVE
CVE-2026-48561
Severity
CRITICAL
CVSS
9.6
EPSS
0.76%
Microsoft
Original NVD Description
Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to execute code over a network.
Related CVEs
Other vulnerabilities affecting the same vendor(s)