SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-50517

CRITICAL · CVSS 9.9 EPSS 1.25%

Source: NVD + CISA KEV + EPSS · Published 2026-07-24 · Last synced 2026-08-23

CyberRota Analysis

AI-Generated

A critical vulnerability exists in M365 Copilot, where deserialization of untrusted data can be exploited by an authorized attacker to execute arbitrary code remotely. This poses a significant risk to the integrity and confidentiality of affected systems, making it imperative for organizations utilizing M365 Copilot to prioritize immediate remediation efforts. Security teams should assess their environments for potential exploitation and implement necessary patches or mitigations.

CVE
CVE-2026-50517
Severity
CRITICAL
CVSS
9.9
EPSS
1.25%

Original NVD Description

Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.

Related CVEs

Other vulnerabilities affecting the same vendor(s)