Remote Code Execution Risk in Microsoft M365 Copilot
CVE-2026-50517
9.9CRITICAL
What is CVE-2026-50517?
A vulnerability in Microsoft M365 Copilot permits an authorized attacker to execute arbitrary code over a network. This flaw arises from the deserialization of untrusted data, which can be exploited in remote code execution attacks. Organizations using M365 Copilot should be aware of this risk and implement recommended patches to safeguard their systems against potential exploitation.
Affected Version(s)
Microsoft 365 Copilot -