Known Vulnerabilities for Copilot Web by Microsoft
Listed below are 10 of the newest known vulnerabilities associated with "Copilot Web" by "Microsoft".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-70335 json | Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual Studi... | Not Provided | 2026-08-11 | 2026-08-13 |
| CVE-2026-69855 json | Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to disclose information over a... | Not Provided | 2026-08-20 | 2026-08-21 |
| CVE-2026-65675 json | No cwe for this issue in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to bypass a security featu... | Not Provided | 2026-08-11 | 2026-08-19 |
| CVE-2026-59864 json | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, `kiota plugin add` and `kiota plugin generate` (with `... | Not Provided | 2026-07-16 | 2026-07-17 |
| CVE-2026-59515 json | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sergey AIWU ai-copilot-... | Not Provided | 2026-07-13 | 2026-07-13 |
| CVE-2026-59118 json | Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network. | Not Provided | 2026-08-07 | 2026-08-11 |
| CVE-2026-58617 json | Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network... | Not Provided | 2026-07-14 | 2026-07-15 |
| CVE-2026-55145 json | Improper neutralization of special elements used in a command ('command injection') in Outlook Copilot allows an authorized a... | Not Provided | 2026-07-14 | 2026-07-22 |
| CVE-2026-54130 json | Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose information over a n... | Not Provided | 2026-06-18 | 2026-06-24 |
| CVE-2026-50519 json | Initialization of a resource with an insecure default in GitHub Copilot and Visual Studio Code allows an unauthorized attacke... | Not Provided | 2026-06-19 | 2026-06-26 |