M365 Copilot command injection CVE-2026-85885 (CVSS 9.9); exclusively hosted / cloud-mitigated
Microsoft Security Update Guide lists CVE-2026-85885 (NVD published 17 September 2026): command injection (CWE-77) in M365 Copilot allowing an authorized (low-privilege) attacker to elevate privileges over the network. Microsoft CVSS 3.1 base 9.9 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). NVD cveTags: exclusively-hosted-service — same September 2026 MSRC cloud-transparency release train as desk cards cve-2026-85887 (Copilot info disclosure 7.7) and cve-2026-85889 (Azure AI Foundry). Expect Microsoft’s hosted-service pattern: CVE published for transparency with mitigation already applied in the service (confirm on MSRC for customer action). Distinct CVE from 85887. Primary: MSRC; secondary: NVD.
- Product
- Microsoft 365 Copilot (exclusively hosted cloud service)
- Versions
- Hosted M365 Copilot service (exclusively-hosted-service tag); confirm MSRC for any customer action
- CVSS
- (CVSS 3.1, Microsoft)
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H - Exploited in Australia?
- unknown
- Patch to
- Confirm MSRC — exclusively hosted; typically no customer patch if Microsoft states fully mitigated in service
Primary: MSRC — CVE-2026-85885 M365 Copilot command injection (Sep 2026) · Vendor: Microsoft Security Update Guide — M365 Copilot · CVE: CVE-2026-85885, CVE-2026-85887, CVE-2026-85889 · NVD — CVE-2026-85885 (exclusively-hosted-service)
