SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-24301

HIGH · CVSS 8.8 EPSS 2.66%

Source: NVD + CISA KEV + EPSS · Published 2026-08-18 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Microsoft Copilot is vulnerable to command injection due to improper neutralization of special elements, enabling unauthorized attackers to potentially disclose sensitive information over a network. Organizations utilizing Microsoft Copilot should prioritize addressing this vulnerability to mitigate the risk of data exposure and maintain the integrity of their systems. Immediate action is recommended for environments where sensitive data is processed or stored.

CVE
CVE-2026-24301
Severity
HIGH
CVSS
8.8
EPSS
2.66%
Microsoft

Original NVD Description

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.

Related CVEs

Other vulnerabilities affecting the same vendor(s)