CVE-2026-50517
Critical · CVSS 9.9- CVSS
- 9.9
- nvd
- EPSS
- 1.25%
- 66th pct
- KEV
- No
- Class
- other
- CWE-502
Description
Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.
References
Status: profiled · ingested 2026-07-29T18:00:00.000Z