Command Injection Vulnerability in M365 Copilot by Microsoft
CVE-2026-85885
9.9CRITICAL
What is CVE-2026-85885?
A command injection vulnerability exists in M365 Copilot, allowing an authorized attacker to exploit improper handling of special command elements. This can potentially lead to elevated privileges over network environments, posing significant security risks.
Affected Version(s)
Microsoft 365 Copilot -