Security Advisory
CVE-2026-48561
9.6
CRITICAL
Vulnerability Description
Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to execute code over a network.
Published Date
July 14, 2026
Official Source
NIST NVD Advisory