CVE-2026-26133 PUBLISHED CVSS 7.099999904632568 HIGH

AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.

EPSS 0.05% · 14.8th percentile

Risk Scores

CVSS v3.1
7.099999904632568
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N/E:U/RL:O/RC:C
EPSS Score
0.05%
14.8th percentile

Affected Products

VendorProductVersions
MicrosoftMicrosoft Edge for iOS1.0.0.0, 1.0.0.0, 1.0.0.0
microsoftpower_bi_android2.0.0, 2.0.0, 2.0.0
microsoftloop2.0.0, 2.0.0, 2.0.0
microsoft365_copilot_iOS1.0, 1.0, 1.0
MicrosoftMicrosoft PowerPoint for iOS1.0, 1.0, 1.0
MicrosoftMicrosoft Word for iOS2.0.0, 2.0.0, 2.0.0
MicrosoftMicrosoft Edge for Android1.0.0, 1.0.0, 1.0.0
microsoftoutlook1.0.0, 1.0.0, 1.0.0
microsoftpowerpoint1.0, 16.0.0.0, 1.0
MicrosoftMicrosoft Word for Android16.0.0.0, 16.0.0.0, 16.0.0.0
MicrosoftN/A
MicrosoftMicrosoft Excel for Android16.0.0.0, 16.0.0.0, 16.0.0.0
microsoftonenote_for_ios1.0.0, 1.0.0, 1.0.0
MicrosoftMicrosoft OneNote for Android16.0.1, 16.0.1, 16.0.1
MicrosoftMicrosoft Outlook for Android1.0, 1.0, 1.0
MicrosoftMicrosoft 365 Copilot for iOS1.0, 1.0, 1.0
microsoftexcel16.0.0.0, 1.0, 16.0.0.0
MicrosoftMicrosoft Teams for Android1.0.0, 1.0.0, 1.0.0
MicrosoftMicrosoft Excel for iOS1.0, 1.0, 1.0
MicrosoftMicrosoft Outlook for iOS1.0.0, 1.0.0, 1.0.0

…and 15 more

Timeline

References

Open in Interactive Console →