LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-42824: CVE-2026-42824 vulnerability

RBRecent Breaches Vulnerability Intelligence
CVSS 6.5 · Medium
6.5
CVSS score
Medium
Severity
Not listed
CISA KEV
No
Ransomware use

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.

Details

WeaknessCWE-77
CVSS base score6.5 (Medium)
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
PublishedJun 4, 2026
Known ransomware useNot documented
Check if your data is exposed →

Frequently asked questions

Is CVE-2026-42824 being actively exploited?

CVE-2026-42824 is tracked in the National Vulnerability Database. It is not currently on CISA’s Known Exploited Vulnerabilities list.

What does CVE-2026-42824 affect?

See the affected products in the official NVD record for CVE-2026-42824.

How do I fix CVE-2026-42824?

Apply the vendor’s patch for the affected software. Then check whether your personal data was exposed in any related breach.

References

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities