External risk intelligence

M365 Copilot Code Execution via Untrusted Data Deserialization.

CVE advisorySeverity: CRITICAL (CVSS 9.9)

CVE-2026-50517

M365 Copilot is a cloud-based, internet-accessible service by design. As an enterprise AI assistant integrated into public-facing productivity suites and cloud interfaces, it is commonly deployed as an internet-reachable application, making the vulnerable surface likely to be exposed to network-based interaction in typical use.

Deserialization

Microsoft 365 Copilot

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in M365 Copilot, a widely used AI assistant for Microsoft 365 applications. The issue stems from how the system handles untrusted data, potentially allowing an attacker with legitimate access to execute malicious code remotely. This could have significant implications for data confidentiality, integrity, and system availability.

  • Untrusted data can let attackers run code.
  • Affects a key enterprise AI productivity tool.
  • Confirm relevance and assess exposure immediately.

Attack Path

How an attacker could exploit the issue

An attacker with existing access to M365 Copilot could potentially send specially crafted data that the system will deserialize. This process, when handling untrusted input, could lead to an attacker executing arbitrary code remotely.

  • Requires authenticated access.
  • Triggers via deserialization of untrusted data.
  • Risk of remote code execution.

Live Threat

Current exploitation, exposure, and threat context

An authorized attacker could execute arbitrary code over a network in M365 Copilot when processing untrusted serialized data. This could impact the integrity and availability of the service, and potentially lead to the compromise of system data.

  • System data and service integrity.
  • Via network by an authorized user.
  • Code execution and data compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in M365 Copilot, allowing for remote code execution, necessitates swift action. Owners of the M365 Copilot deployment, likely platform or security teams, must first confirm the precise scope of exposure and identify critical business functions relying on this service. A coordinated response involving vendor management and application owners will be crucial for risk-based remediation planning.

  • Platform or security teams own the vulnerability.
  • Verify M365 Copilot exposure and critical dependencies.
  • Coordinate vendor response and plan remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is M365 Copilot?

M365 Copilot is an enterprise AI assistant integrated into the Microsoft 365 productivity suite. It uses advanced language models to help users analyze data, draft documents, and automate tasks within business applications. Because it processes large amounts of organizational information, it acts as a central hub for workplace productivity and data interaction.

What does deserialization of untrusted data mean for CVE-2026-50517?

This vulnerability is classified as CWE-502, which occurs when an application takes data from an untrusted source and transforms it into a complex object without sufficient validation. In the case of CVE-2026-50517, the system is tricked into executing hidden instructions contained within that data, allowing an attacker to run their own code on the underlying infrastructure.

How is this M365 Copilot vulnerability triggered?

The flaw is triggered when an attacker with authorized access sends specially crafted, malicious data to the system for processing. Simply using the application for standard tasks does not trigger the bug; the attacker must intentionally submit malformed serialized input designed to exploit the way the system interprets incoming data structures.

Is my organization at risk from this vulnerability?

Halo Surface Signal indicates that because M365 Copilot is a cloud-based service designed for web accessibility, it is likely to be reachable over the network. Organizations using this tool should assume the service is internet-facing, as it is integrated into cloud interfaces used by staff. You are potentially at risk if your environment utilizes this AI assistant.

What should I do first to address CVE-2026-50517?

Begin by identifying which teams in your organization manage your M365 Copilot deployment and which critical business processes depend on it. Do not attempt manual patches; coordinate with your platform administrators to monitor for vendor guidance and track the status of official updates. Prioritize assessing how this service integrates with your sensitive data.

References