CVE-2026-42895 | Microsoft Copilot command injection (EUVD-2026-38087 / WID-SEC-2026-2020)
A vulnerability, which was classified as critical, has been found in Microsoft Copilot. Affected by this vulnerability is an unknown functionality. The manipulation leads to command injection.
This vulnerability is uniquely identified as CVE-2026-42895. The attack can only be initiated within the local network. No exploit exists.