Known Vulnerabilities for M365 by Ui
Listed below are 3 of the newest known vulnerabilities associated with "M365" by "Ui".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
More device details and information can be found at device.report here: Ui M365
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-54130 json | Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose information over a n... | Not Provided | 2026-06-18 | 2026-06-24 |
| CVE-2026-50517 json | Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network. | Not Provided | 2026-07-24 | 2026-07-28 |
| CVE-2026-42827 json | Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized at... | Not Provided | 2026-05-22 | 2026-06-19 |
| CVE-2026-42824 json | Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized at... | Not Provided | 2026-06-04 | 2026-07-15 |
| CVE-2026-41106 json | Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges ove... | Not Provided | 2026-07-02 | 2026-07-07 |
| CVE-2026-26164 json | Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized at... | Not Provided | 2026-05-07 | 2026-06-01 |
| CVE-2026-26129 json | Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized at... | Not Provided | 2026-05-07 | 2026-06-01 |
| CVE-2026-16053 json | Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820 are affected to Authenticated Path Trave... | Not Provided | 2026-08-11 | 2026-08-11 |
| CVE-2026-11374 json | In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated to a... | Not Provided | 2026-06-23 | 2026-06-24 |
| CVE-2020-8171 json | We have recently released new version of AirMax AirOS firmware v6.3.0 for TI, XW and XM boards that fixes vulnerabilities fou... | 9.8 - CRITICAL | 2020-05-26 | 2020-05-28 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Ui | M365 | - |