Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 08 Jun 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microsoft copilot
|
|
| CPEs | cpe:2.3:a:microsoft:copilot:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Microsoft copilot
|
Fri, 05 Jun 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 04 Jun 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an authorized attacker to execute code over a network. | |
| Title | Microsoft M365 Copilot Remote Code Execution Vulnerability | |
| First Time appeared |
Microsoft
Microsoft 365 Copilot |
|
| Weaknesses | CWE-77 | |
| CPEs | cpe:2.3:a:microsoft:365_copilot:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Microsoft
Microsoft 365 Copilot |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2026-06-26T19:42:33.435Z
Reserved: 2026-05-12T16:07:22.618Z
Link: CVE-2026-45497
Updated: 2026-06-05T10:49:26.307Z
Status : Analyzed
Published: 2026-06-04T23:17:32.250
Modified: 2026-06-08T13:55:28.053
Link: CVE-2026-45497
No data.
OpenCVE Enrichment
Updated: 2026-06-05T00:45:26Z