Vulnerability · NVD
CVE-2026-26133
CVE-2026-26133, high severity (CVSS 7.1): 14 tracked apps concerned, all fixed or indeterminable on their current version.
- Severity (CVSS)
- 7.1
- Exploitation
- 0.5 %
- Tracked apps
- 14
- Still exposed
- 0
NVD scale
EPSS, predicted over 30 days
AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.
Attack vector : Network
No privileges required
Show raw CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
EPSS
0.54%
exploit very unlikely
percentile 43.1%
Tracked apps referencing this CVE
For each app: the affected range, the fixing version, and where the tracked app stands today.
-
Observed affected builds (15)
-
Observed affected builds (20)
16.0.19725.20108 16.0.19725.20058 16.0.19127.20134 16.0.18925.20074 16.0.17726.20080 16.0.17328.20152 16.0.17231.20130 16.0.16924.20064 16.0.13801.20162 16.0.13628.20214 16.0.13530.20130 16.0.13231.20130 16.0.13029.20182 16.0.12430.20120 16.0.11929.20222 16.0.11901.20110 16.0.11126.20063 16.0.11029.20056 16.0.10827.20078 16.0.10730.20043 -
-
-
-
-
-
Observed affected builds (27)
16.0.19725.20058 16.0.19628.20074 16.0.19530.20070 16.0.19328.20086 16.0.19231.20090 16.0.19127.20134 16.0.19029.20110 16.0.18526.20030 16.0.18429.20094 16.0.18324.20086 16.0.17830.20082 16.0.17328.20152 16.0.16501.20160 16.0.15629.20092 16.0.15427.20090 16.0.15128.20206 16.0.14729.20146 16.0.14527.20162 16.0.14326.20140 16.0.14228.20138 16.0.13801.20162 16.0.13127.20162 16.0.13029.20182 16.0.12624.20254 16.0.12130.20208 16.0.11001.20074 16.0.10827.20078
Vulnerable CPE configurations (20)
| Vendor | Product | Platform | Versions | CPE 2.3 URI |
|---|---|---|---|---|
| microsoft |
365_copilot iOS
|
iOS | <2.107.2 | cpe:2.3:a:microsoft:365_copilot:*:*:*:*:*:iphone_os:*:* |
| microsoft |
365_copilot Android
|
Android | <16.0.19815.10000 | cpe:2.3:a:microsoft:365_copilot:*:*:*:*:*:android:*:* |
| microsoft |
edge Android
|
Android | <145.3800.99 | cpe:2.3:a:microsoft:edge:*:*:*:*:*:android:*:* |
| microsoft |
edge iOS
|
iOS | <145.3800.99 | cpe:2.3:a:microsoft:edge:*:*:*:*:*:iphone_os:*:* |
| microsoft |
excel iOS
|
iOS | <2.106.2 | cpe:2.3:a:microsoft:excel:*:*:*:*:*:iphone_os:*:* |
| microsoft |
excel Android
|
Android | <16.0.19822.20038 | cpe:2.3:a:microsoft:excel:*:*:*:*:*:android:*:* |
| microsoft |
loop iOS
|
iOS | <2.106 | cpe:2.3:a:microsoft:loop:*:*:*:*:*:iphone_os:*:* |
| microsoft |
onenote Android
|
Android | <16.0.19725.20142 | cpe:2.3:a:microsoft:onenote:*:*:*:*:*:android:*:* |
| microsoft |
onenote iOS
|
iOS | - | cpe:2.3:a:microsoft:onenote:-:*:*:*:*:iphone_os:*:* |
| microsoft |
outlook Android
|
Android | <5.2605.0 | cpe:2.3:a:microsoft:outlook:*:*:*:*:*:android:*:* |
| microsoft |
outlook iOS
|
iOS | <5.2605.0 | cpe:2.3:a:microsoft:outlook:*:*:*:*:*:iphone_os:*:* |
| microsoft |
outlook macOS
|
macOS | - | cpe:2.3:a:microsoft:outlook:-:*:*:*:*:macos:*:* |
| microsoft |
power_bi Android
|
Android | <2.2.260210.21290750 | cpe:2.3:a:microsoft:power_bi:*:*:*:*:*:android:*:* |
| microsoft |
power_bi iOS
|
iOS | - | cpe:2.3:a:microsoft:power_bi:-:*:*:*:*:iphone_os:*:* |
| microsoft |
powerpoint iOS
|
iOS | <2.106.2 | cpe:2.3:a:microsoft:powerpoint:*:*:*:*:*:iphone_os:*:* |
| microsoft |
powerpoint Android
|
Android | <16.0.19822.20038 | cpe:2.3:a:microsoft:powerpoint:*:*:*:*:*:android:*:* |
| microsoft |
teams Android
|
Android | <1.0.0.2026043102 | cpe:2.3:a:microsoft:teams:*:*:*:*:*:android:*:* |
| microsoft |
teams iOS
|
iOS | <8.3.1 | cpe:2.3:a:microsoft:teams:*:*:*:*:*:iphone_os:*:* |
| microsoft |
word iOS
|
iOS | <2.106.2 | cpe:2.3:a:microsoft:word:*:*:*:*:*:iphone_os:*:* |
| microsoft |
word Android
|
Android | <16.0.19822.20038 | cpe:2.3:a:microsoft:word:*:*:*:*:*:android:*:* |
Manage your fleet with Appaloosa
Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.