Microsoft Discloses CVE-2026-45497, a Command-Injection RCE in 365 Copilot Already Fixed Server-Side With No Customer Action
Microsoft rated the Copilot command-injection flaw Critical, with a 7.7 CVSS base score. It was already mitigated in the cloud and not exploited.