Filtered by vendor Microsoft Subscriptions
Filtered by product 365 Word Copilot Subscriptions
Total 2 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2026-21521 1 Microsoft 1 365 Word Copilot 2026-01-23 7.4 High
Improper neutralization of escape, meta, or control sequences in Copilot allows an unauthorized attacker to disclose information over a network.
CVE-2025-59252 1 Microsoft 3 365, 365 Copilot, 365 Word Copilot 2026-01-02 9.3 Critical
Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network.