Microsoft
Microsoft 365 Copilot Chat: vulnerabilidades y CVE
Microsoft 365 Copilot Chat tiene 7 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses5
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-26164 | Alta (7.5) | 1.0% | — | 7 may 2026 | Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-26129 | Alta (7.5) | 1.0% | — | 7 may 2026 | Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-26137 | Crítica (9.9) | 0.72% | — | 19 mar 2026 | Server-side request forgery (ssrf) in Microsoft Exchange allows an authorized attacker to elevate privileges over a network. |
| CVE-2025-59286 | Crítica (9.3) | 0.57% | — | 9 oct 2025 | Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network. |
| CVE-2025-59272 | Crítica (9.3) | 0.57% | — | 9 oct 2025 | Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to perform information disclosure locally. |
| CVE-2025-53787 | Alta (7.5) | 0.71% | — | 7 ago 2025 | Microsoft 365 Copilot BizChat Information Disclosure Vulnerability |
| CVE-2025-53774 | Alta (7.5) | 0.61% | — | 7 ago 2025 | Microsoft 365 Copilot BizChat Information Disclosure Vulnerability |