CVE-2026-42895: Microsoft Copilot Command Injection Flaw
🟠 High | Source: Microsoft Security Response Center A command injection vulnerability in Microsoft Copilot allows an unauthenticated attacker to tamper with the service over a network, without requiring any user interaction or elevated privileges. The flaw stems from improper handling of special characters within commands, a class of vulnerability that can enable attackers to manipulate application behaviour or underlying systems. Given Copilot’s integration across Microsoft 365 and Azure services, the potential blast radius for affected organisations is significant. ...