A vulnerability, which was classified as critical, was found in Microsoft Copilot. This vulnerability affects unknown code. Such manipulation leads to command injection.
This vulnerability is traded as CVE-2026-26136. The attack may be launched remotely. There is no exploit available.
This product is a managed service, indicating that users are not permitted to maintain vulnerability countermeasures themselves.