Microsoft disclosed CVE-2026-50517, a critical remote code execution flaw in Microsoft 365 Copilot caused by deserialization of untrusted data (CWE-502). The vulnerability allows an authenticated attacker with low privileges to execute code over the network without user interaction, and carries a CVSS 3.1 score of 9.9 with the vector AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, indicating high impact across confidentiality, integrity, and availability with changed scope.
The issue affects the hosted Microsoft 365 Copilot service, and Microsoft remediated it on the service side rather than through a customer-installed patch. Reporting indicated all versions of M365 Copilot were affected, while no active exploitation had been publicly reported at the time of disclosure. Organizations were advised to confirm tenant coverage, review Copilot permissions and access, enable auditing, and monitor for unusual Copilot-related activity.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Microsoft remediated CVE-2026-50517 on the managed M365 Copilot service side, meaning customers did not need to apply a local patch. The reporting also stated that all versions of Microsoft 365 Copilot were affected and that no active exploitation had been reported at the time of publication.
Microsoft published a vulnerability reference for CVE-2026-50517 in the MSRC update guide on 2026-07-24. The issue affects Microsoft 365 Copilot and is described as a deserialization of untrusted data flaw that can allow authenticated remote code execution over a network.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.