Security Advisory

CVE-2026-48561

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-14 17:04:12
Last updated 2026-07-27 23:45:48
Assigner microsoft
CVSS score 9.6
State PUBLISHED

Description

Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to execute code over a network.