CVE-2026-85885CriticalCVSS 9.9

Microsoft 365 Copilot Elevation of Privilege Vulnerability

Published
September 17, 2026
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized attacker to elevate privileges over a network.

🎯 Affected products1

  • Microsoft 365 Copilot

🔗 References (1)