OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-85885

CRITICAL · CVSS 9.9 EPSS 0.72%

Source: NVD + CISA KEV + EPSS · Published 2026-09-17 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

M365 Copilot is vulnerable to a command injection flaw that allows authorized attackers to execute arbitrary commands, potentially leading to privilege escalation across the network. This critical vulnerability, with a CVSS score of 9.9, poses significant risks to organizations utilizing M365 Copilot, making it imperative for security teams to prioritize immediate remediation efforts.

CVE
CVE-2026-85885
Severity
CRITICAL
CVSS
9.9
EPSS
0.72%

Original NVD Description

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized attacker to elevate privileges over a network.

Related CVEs

Other vulnerabilities affecting the same vendor(s)