CyberRota Analysis
AI-GeneratedA critical vulnerability exists in M365 Copilot, where deserialization of untrusted data can be exploited by an authorized attacker to execute arbitrary code remotely. This poses a significant risk to the integrity and confidentiality of affected systems, making it imperative for organizations utilizing M365 Copilot to prioritize immediate remediation efforts. Security teams should assess their environments for potential exploitation and implement necessary patches or mitigations.
CVE
CVE-2026-50517
Severity
CRITICAL
CVSS
9.9
EPSS
1.25%
Original NVD Description
Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.
Related CVEs
Other vulnerabilities affecting the same vendor(s)