CVE-2026-50517
Microsoft · Microsoft 365 Copilot
A deserialization of untrusted data vulnerability in Microsoft 365 Copilot allows an authorized attacker to execute code over a network.
Executive summary
A critical deserialization flaw in Microsoft 365 Copilot enables an authenticated attacker to achieve remote code execution.
Vulnerability
This vulnerability involves the insecure deserialization of untrusted data within Microsoft 365 Copilot. The attack requires an authorized user with legitimate credentials to trigger the flaw, as it does not permit initial unauthorized access to the environment.
Business impact
Successful exploitation of this vulnerability could lead to a full compromise of the affected system, including unauthorized code execution, data exfiltration, or lateral movement. With a CVSS score of 9.9, this vulnerability is classified as critical, representing a severe risk to organizational security and data integrity.
Remediation
Immediate Action: Review the Microsoft Security Response Center (MSRC) update guide for the latest patches and apply them to all affected instances immediately.
Proactive Monitoring: Monitor network traffic and system access logs for anomalous behavior or unauthorized process execution originating from authenticated user accounts.
Compensating Controls: Ensure robust Identity and Access Management (IAM) controls are in place to limit the impact of compromised credentials, and utilize endpoint detection and response (EDR) tools to identify suspicious deserialization activity.
Exploitation status
Public Exploit Available: False
Analyst recommendation
Given the critical nature of this vulnerability and the potential for severe system impact, organizations should prioritize the immediate application of vendor-supplied patches. Security teams must ensure that all relevant Microsoft 365 Copilot instances are updated to the latest available version to mitigate the risk of exploitation.