Critical Security Flaws Identified in Microsoft 365 Copilot by CERT-In
CERT-In flags critical security vulnerabilities in Microsoft 365 Copilot

Image: Deccan Herald
The Indian Computer Emergency Response Team (CERT-In) has identified two critical vulnerabilities in Microsoft 365 Copilot, which could allow cybercriminals to execute arbitrary code and steal sensitive information. Users are urged to update their applications to mitigate these risks.
- 01CERT-In has flagged vulnerabilities CVE-2026-42827 and CVE-2026-41090 in Microsoft 365 Copilot.
- 02The identified issues include input validation flaws, authentication weaknesses, and command handling errors.
- 03If not addressed, these vulnerabilities could lead to arbitrary code execution and denial of service.
- 04Other Microsoft products, including Microsoft Global Secure Access and Azure Stack ACI, also have security issues.
- 05Microsoft has acknowledged these vulnerabilities and released updates to address them.
Advertisement
In-Article Ad
The Indian Computer Emergency Response Team (CERT-In) has reported critical security vulnerabilities in Microsoft 365 Copilot, specifically CVE-2026-42827 and CVE-2026-41090. These vulnerabilities pose significant risks, including the potential for attackers to execute arbitrary code, steal sensitive information, and disrupt cloud services. CERT-In highlighted issues related to input validation, authentication, and command handling flaws. In addition to Microsoft 365 Copilot, other Microsoft products such as Microsoft Global Secure Access and Azure Stack ACI are also affected by security vulnerabilities. Microsoft has acknowledged these issues and has rolled out updates to address them. Users are strongly advised to update their applications to the latest version to safeguard their data and ensure security. The update process involves accessing any Microsoft 365 application, navigating to the Account section, and selecting 'Update Now.' Failure to update could leave users vulnerable to cyber threats.
Advertisement
In-Article Ad
The vulnerabilities could allow cybercriminals to access sensitive data, affecting both individual users and organizations.
Advertisement
In-Article Ad
Reader Poll
Have you updated your Microsoft 365 applications following the security alerts?
Connecting to poll...
More about Indian Computer Emergency Response Team
Read the original article
Visit the source for the complete story.






