Vulnerability
Published 2026-09-17
Verified 2026-09-19

M365 Copilot incorrect permissions CVE-2026-85887 (CVSS 7.7); cloud-mitigated info disclosure

Microsoft Security Update Guide (September 2026; MSRC releaseDate 17 September 2026 PDT) lists CVE-2026-85887, an M365 Copilot information-disclosure vulnerability: incorrect permission assignment for a critical resource (CWE-732) lets an authorized (low-privilege) attacker disclose information over the network. Microsoft CVSS 3.1 base 7.7 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N); MSRC severity Critical / impact Information Disclosure. Exclusively hosted service: Microsoft states the issue is already fully mitigated — no customer patch steps; CVE published for cloud transparency. MSRC: publicly disclosed No; exploited No. NVD received 18 September 2026 00:17 UTC. Distinct from Azure AI Foundry CVE-2026-85889/85917. Primary: MSRC; secondary: NVD.

Product
Microsoft 365 Copilot (exclusively hosted cloud service)
Versions
Hosted M365 Copilot service; Microsoft states already fully mitigated (no on-prem build to patch)
CVSS
(CVSS 3.1, Microsoft High/Critical class)
Exploited in Australia?
unknown
Patch to
No customer action — Microsoft states fully mitigated in the hosted M365 Copilot service (transparency CVE)

Primary: MSRC — CVE-2026-85887 M365 Copilot information disclosure (17 Sep 2026) · Vendor: Microsoft Security Update Guide — M365 Copilot · CVE: CVE-2026-85887, CVE-2026-85889 · NVD — CVE-2026-85887 (received 18 Sep 2026)

vulnerabilities ai cloud