Microsoft
Microsoft 365 Copilot: vulnerabilidades y CVE
Microsoft 365 Copilot tiene 55 vulnerabilidades publicadas, 36 de ellas en los últimos 12 meses. 9 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE55
Últimos 12 meses36
Críticas9
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-85887 | Alta (7.7) | 0.84% | — | 18 sept 2026 | Incorrect permission assignment for critical resource in M365 Copilot allows an authorized attacker to disclose information over a network. |
| CVE-2026-85885 | Alta (8.8) | 0.72% | — | 17 sept 2026 | Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-78501 | Alta (7.4) | 0.89% | — | 17 sept 2026 | Improper neutralization of special elements used in a command ('command injection') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-50517 | Crítica (9.9) | 1.7% | — | 24 jul 2026 | Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network. |
| CVE-2026-58617 | Crítica (9.8) | 0.79% | — | 14 jul 2026 | Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2026-50387 | Alta (7.8) | 0.33% | — | 14 jul 2026 | Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges locally. |
| CVE-2026-48561 | Crítica (9.6) | 0.86% | — | 14 jul 2026 | Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to execute code over a network. |
| CVE-2026-41106 | Crítica (9.3) | 0.72% | — | 2 jul 2026 | Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2026-47645 | Alta (8.8) | 0.76% | — | 19 jun 2026 | Url redirection to untrusted site ('open redirect') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2026-42895 | Alta (7.5) | 0.71% | — | 19 jun 2026 | Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network. |
| CVE-2026-54130 | Alta (7.5) | 1.1% | — | 18 jun 2026 | Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-45474 | Alta (8.4) | 0.36% | — | 9 jun 2026 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. |
| CVE-2026-45472 | Alta (8.4) | 0.36% | — | 9 jun 2026 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. |
| CVE-2026-45463 | Alta (8.4) | 0.36% | — | 9 jun 2026 | Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally. |
| CVE-2026-45461 | Alta (8.4) | 0.36% | — | 9 jun 2026 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. |
| CVE-2026-45460 | Media (4.7) | 0.42% | — | 9 jun 2026 | Buffer over-read in Microsoft Office allows an unauthorized attacker to disclose information locally. |
| CVE-2026-42827 | Alta (7.5) | 0.92% | — | 22 may 2026 | Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-41090 | Crítica (9.3) | 0.76% | — | 22 may 2026 | Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network. |
| CVE-2026-42831 | Alta (7.8) | 0.47% | — | 12 may 2026 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. |
| CVE-2026-41614 | Media (6.2) | 0.40% | — | 12 may 2026 | Improper access control in M365 Copilot for Desktop allows an unauthorized attacker to perform spoofing locally. |
| CVE-2026-41100 | Media (4.4) | 0.26% | — | 12 may 2026 | Improper access control in M365 Copilot allows an authorized attacker to perform spoofing locally. |
| CVE-2026-40363 | Alta (8.4) | 0.36% | — | 12 may 2026 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. |
| CVE-2026-33102 | Crítica (9.3) | 0.72% | — | 23 abr 2026 | Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2026-24299 | Media (5.3) | 0.65% | — | 19 mar 2026 | Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-26133 | Alta (7.1) | 0.54% | — | 16 mar 2026 | AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-26134 | Alta (7.8) | 0.33% | — | 10 mar 2026 | Integer overflow or wraparound in Microsoft Office allows an authorized attacker to elevate privileges locally. |
| CVE-2026-26110 | Alta (7.8) | 0.34% | — | 10 mar 2026 | Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. |
| CVE-2026-25180 | Media (5.5) | 0.66% | — | 10 mar 2026 | Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to disclose information locally. |
| CVE-2026-24285 | Alta (7) | 0.46% | — | 10 mar 2026 | Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. |
| CVE-2026-24307 | Alta (7.5) | 0.92% | — | 22 ene 2026 | Improper validation of specified type of input in M365 Copilot allows an unauthorized attacker to disclose information over a network. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.