A vulnerability, which was classified as critical, was found in Microsoft Copilot. This vulnerability affects unknown code. Such manipulation leads to command injection.

This vulnerability is traded as CVE-2026-26136. The attack may be launched remotely. There is no exploit available.

This product is a managed service, indicating that users are not permitted to maintain vulnerability countermeasures themselves.