What is CVE-2026-50517?
A deserialization of untrusted data vulnerability in M365 Copilot allows an authorized attacker to execute code over a network. This can be exploited by authenticated users via specially crafted data. Immediate patching with Microsoft's security update is required to mitigate the risk.
Azərbaycanca: M365 Copilot-da etibarsız verilənlərin deserialization zəifliyi səlahiyyətli hücumçuya şəbəkə üzərindən kod icra etməyə imkan verir. Bu, təsdiqlənmiş istifadəçilər tərəfindən xüsusi hazırlanmış verilənlərlə istismar edilə bilər. İstismar riskini azaltmaq üçün dərhal Microsoft tərəfindən buraxılmış təhlükəsizlik yeniləməsi tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-502; shared vendor: Microsoft
FAQ2
What is the CVE-2026-50517 vulnerability in M365 Copilot?
It is a deserialization of untrusted data vulnerability in M365 Copilot. It allows an authorized attacker to execute code over a network.
How can the risk of CVE-2026-50517 be mitigated?
To mitigate the exploitation risk, the security update provided by Microsoft must be applied immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.