View Ridge Security
Back to Cyber HoseVulnerabilities & CVEs

Critical RCE Vulnerability Found in Microsoft M365 Copilot

🔓 VULNERABILITIES & CVEs

  • Critical RCE Vulnerability Found in Microsoft M365 Copilot — CVE ThreatInt
    Microsoft M365 Copilot has a critical remote code execution vulnerability via deserialization of untrusted data.

    • Applies to Microsoft M365 Copilot product
    • Vulnerability involves deserialization of untrusted data
    • Allows authorized attackers to execute code remotely over a network
    • CVSS score is 9.9, indicating critical severity
    • Requires low attack complexity and privileges, no user interaction needed
  • Critical Heap-Based Buffer Overflow in Microsoft Account Enables Remote Code Execution — CVE ThreatInt
    A heap-based buffer overflow in Microsoft Account allows remote code execution by attackers.

    • Applies to Microsoft Account product
    • Vulnerability is a heap-based buffer overflow
    • Allows unauthorized remote code execution over a network
    • Has a critical severity score of 9.8 CVSS 3.1
    • No privileges or user interaction required for exploitation
  • Azure API Management suffers high-severity remote code execution flaw CVE-2026-35425 — CVE ThreatInt
    Azure API Management has a remote code execution vulnerability exploitable by authorized users.

    • Applies to Azure API Management (APIM) service
    • Vulnerability is improper access control allowing remote code execution
    • Requires attacker to have authorized access (high privileges)
    • Exploited remotely over the network without user interaction
    • CVSS 8.0, CWE-284, affects confidentiality, integrity, and availability
  • Microsoft Surface Remote Code Execution VulnerabilityImproper input validatio... — CVE ThreatInt
    Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.

  • CVE-2026-58275 — CVSS 10.0 — Azure DNS Elevation of Privilege Vulnerability
    Missing authorization in Azure DNS leads to elevation of privilege.

  • CVE-2026-62825 — CVSS 10.0 — Azure Key Vault Elevation of Privilege Vulnerability
    Improper authentication in Azure Key Vault allows elevation of privilege.

  • CVE-2026-56191 — CVSS 10.0 — Microsoft Exchange Online Tampering Vulnerability
    Improper authentication in Microsoft Exchange Online leads to tampering vulnerability.

  • CVE-2026-56160 — CVSS 9.1 — Azure Red Hat OpenShift (ARO) Elevation of Privilege Vulnerability
    Improper authentication in Azure Red Hat OpenShift allows elevation of privilege.

  • CVE-2026-56167 — CVSS 8.5 — Azure AI Search Elevation of Privilege Vulnerability
    Server-side request forgery in Azure AI Search leads to elevation of privilege.

  • CVE-2026-49159 — CVSS 6.5 — Microsoft Graph Information Disclosure Vulnerability
    Exposure of sensitive information in Microsoft Graph due to information disclosure vulnerability.

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check