Remote Code Execution Risk in Microsoft M365 Copilot
CVE-2026-50517

9.9CRITICAL

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
24 July 2026

What is CVE-2026-50517?

A vulnerability in Microsoft M365 Copilot permits an authorized attacker to execute arbitrary code over a network. This flaw arises from the deserialization of untrusted data, which can be exploited in remote code execution attacks. Organizations using M365 Copilot should be aware of this risk and implement recommended patches to safeguard their systems against potential exploitation.

Affected Version(s)

Microsoft 365 Copilot -

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.