CVE-2026-48561CriticalRevised 24 Jul
Microsoft Edge Copilot Remote Code Execution Vulnerability
Assessment
Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to execute code over a network.
- Severity
- Critical
- CVSS base score
- Not published
- Impact
- Remote Code Execution
- EPSS, next 30 days
- 0.9%Higher than 56.9% of scored CVEs · FIRST model run 26 Sep 2026 · about EPSS
- Exploitability
- Exploitation Less Likely
- Publicly disclosed
- No
- Customer action
- Required: apply the update
- Component
- Copilot Chat (Microsoft Edge)
- Weakness
- CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')
- Issued by
- Microsoft
- Published
- 14 Jul 2026 · July 2026
- Last revised
- 24 Jul 2026Corrected the CVE description and title. This is an informational change only.
Updates that fix it
0 KBsNo KB listed
MSRC lists no downloadable update, which usually means a service-side fix or a release-notes update. Check the MSRC advisory.
Affected products
Browser2 affected products
- Microsoft Edge Copilot for Android
- Microsoft Edge Copilot for IOS