CVE-2026-42824: CVE-2026-42824 vulnerability
CVSS 6.5 · Medium
6.5
CVSS score
Medium
Severity
Not listed
CISA KEV
No
Ransomware use
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.
Details
WeaknessCWE-77
CVSS base score6.5 (Medium)
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NPublishedJun 4, 2026
Known ransomware useNot documented
Frequently asked questions
Is CVE-2026-42824 being actively exploited?
CVE-2026-42824 is tracked in the National Vulnerability Database. It is not currently on CISA’s Known Exploited Vulnerabilities list.
What does CVE-2026-42824 affect?
See the affected products in the official NVD record for CVE-2026-42824.
How do I fix CVE-2026-42824?
Apply the vendor’s patch for the affected software. Then check whether your personal data was exposed in any related breach.