SYS::ONLINE
Wasteland.
Briefs1521
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-50517 2026-07-23

CVE-2026-50517: Critical Deserialization Flaw in Microsoft 365 Copilot Enables Remote Code Execution

"A critical (CVSS 9.9) deserialization vulnerability in Microsoft 365 Copilot allows an authenticated attacker to execute code over a network."

A critical (CVSS 9.9) deserialization vulnerability in Microsoft 365 Copilot allows an authenticated attacker to execute code over a network.

What Is It

CVE-2026-50517 is a deserialization-of-untrusted-data flaw (CWE-502) in Microsoft 365 Copilot. According to Microsoft's advisory, the weakness "allows an authorized attacker to execute code over a network." It carries a CVSS 3.1 base score of 9.9 (CRITICAL), with the vector AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. The attack is network-based with low complexity, requires only low privileges, and needs no user interaction. The scope is marked "Changed," and confidentiality, integrity, and availability impacts are all rated High.

Why It Matters

Deserialization flaws that lead to code execution are among the most severe classes of vulnerability. The near-maximum 9.9 score reflects that an authenticated attacker can compromise the service with low effort and no victim interaction, achieving full impact across confidentiality, integrity, and availability. The "Changed" scope indicates the impact can extend beyond the initially vulnerable component. Microsoft tags this as an exclusively-hosted-service issue, meaning it affects Microsoft's cloud offering.

What's Vulnerable

The affected product is Microsoft 365 Copilot (vendor: Microsoft). The affected version is listed as "-", indicating the hosted service as a whole rather than a specific installable build. No affected CPEs are enumerated in the supplied data.

Patch Status

Because this is an exclusively-hosted-service vulnerability, remediation is handled by Microsoft on the service side. Users should consult Microsoft's MSRC update guide for the authoritative status. The supplied source material contains no CISA KEV entry, so there is no confirmation of active exploitation and no CISA-mandated remediation action in the data provided. The record status in the supplied data is "Received."

Sources