A vulnerability marked as critical has been reported in Microsoft Copilot. This affects an unknown function. The manipulation leads to deserialization.

This vulnerability is documented as CVE-2026-50517. The attack can be initiated remotely. There is not any exploit available.

This product is available as a managed service. Users are not able to maintain vulnerability countermeasures themselves.