CVE-2026-41090General(microsoft / 365_copilot)

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch microsoft 365_copilot systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • 365_copilot

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • General: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-05-27); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
365_copilot

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-05-23: 1Mentions · 2026-05-27: 2Mentions · 2026-06-16: 1Patch / Workaround · 2026-05-27: 2Technical Details · 2026-05-23: 1Technical Details · 2026-05-27: 205-2305-2706-16
Signal classification2 categories
General
250.0%
Patch
250.0%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-05-231
General1
2026-05-272
Patch2
2026-06-161
General1
Full discourse4 posts
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Patch

    ثغرة Command Injection في Microsoft Copilot 📍 CVE-2026-41090 | 🔴 CRITICAL 9.3 | مايحتاج تسوي اي شي لان الخدمة سحابيه وتم اغلاق الثغرة من قبل مايكروسفت مثل الي صار مع الثغره في التغريدة المقتبسه https://t.co/x4LYQMD8Ys

    Post summary

    Microsoft has closed CVE-2026-41090, a critical Command Injection flaw in Copilot; no evidence of active exploitation or PoC, but a patch has been applied.

    000241.8K
    50.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-41090 Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a n… https://www.cve.org/CVERecord?id=CVE-2026-41090

    Post summary

    The snippet provides a brief description of a command‑injection vulnerability in Microsoft Copilot (CVE-2026-41090) but offers no details on PoCs, exploitation, or mitigation actions.

    00020237
    57.8K followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-41090: Microsoft Copilot Command Injection Bug - What It Means for Your Business and How to Respond https://hubs.li/Q04lz53c0

    Post summary

    The provided text only references a CVE and a link to an article, without detailing any exploit, patch, or technical information.

    0000027
    31 followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 CRITICAL: CVE-2026-41090 (CVSS 9.3) - Command injection vulnerability in Microsoft Copilot allows remote tampering. No authentication required. Patch immediately. #CVE #PatchNow #ThreatIntel https://t.co/OBTwYN6NEb

    Post summary

    Critical command injection in Microsoft Copilot (CVE-2026-41090) with CVSS 9.3, no authentication required; immediate patching is advised, but no active exploitation or PoC is reported.

    0000057
    30 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoft365_copilot-iphone_os-

Explore more