Microsoft
Microsoft Copilot: vulnerabilidades y CVE
Microsoft Copilot tiene 7 vulnerabilidades publicadas, 7 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses7
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-55946 | Media (5.9) | 0.39% | — | 17 sept 2026 | Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-24301 | Alta (7.5) | 4.1% | — | 18 ago 2026 | Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-55145 | Alta (7.1) | 0.53% | — | 14 jul 2026 | Improper neutralization of special elements used in a command ('command injection') in Outlook Copilot allows an authorized attacker to perform tampering over a network. |
| CVE-2026-45497 | Alta (8.8) | 0.61% | — | 4 jun 2026 | Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an authorized attacker to execute code over a network. |
| CVE-2026-42824 | Alta (7.5) | 0.92% | — | 4 jun 2026 | Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-42869 | Crítica (10) | 0.78% | — | 11 may 2026 | SOCFortress CoPilot focuses on providing a single pane of glass for all your security operations needs. Prior to 0.1.57, SOCFortress CoPilot ships a hardcoded JWT signing secret as a fallback value in… |
| CVE-2026-26136 | Alta (7.5) | 0.92% | — | 19 mar 2026 | Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network. |