Command Injection Vulnerability in M365 Copilot by Microsoft
CVE-2026-85885

9.9CRITICAL

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
17 September 2026

What is CVE-2026-85885?

A command injection vulnerability exists in M365 Copilot, allowing an authorized attacker to exploit improper handling of special command elements. This can potentially lead to elevated privileges over network environments, posing significant security risks.

Affected Version(s)

Microsoft 365 Copilot -

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.