CVE-2026-41106
published 2026-07-02CVE-2026-41106: Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.
PriorityP352critical9.3CVSS 3.1
AVNACLPRNUIRSCCHIHAN
EPSS
0.72%
51.5th percentile
Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_365_copilot | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Microsoft 365 Copilot redirect (EUVD-2026-41445)
vuldb·2026-07-04·CVSS 9.3
CVE-2026-41106 [CRITICAL] Microsoft 365 Copilot redirect (EUVD-2026-41445)
A vulnerability categorized as problematic has been discovered in Microsoft 365 Copilot. This affects an unknown part. Executing a manipulation can lead to open redirect.
This vulnerability appears as CVE-2026-41106. The attack may be performed from remote. There is no available exploit.
This product is provided as a managed service, meaning users do not have the ability to maintain vulnerability countermeasures themselves.
GHSA
Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.
ghsa_unreviewed·2026-07-03
CVE-2026-41106 [CRITICAL] CWE-601 Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.
Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.
No detection rules found.
No public exploits indexed.
Sans Isc
Microsoft Patch Tuesday July 2026 - The AI Acopolypse is Here , (Tue, Jul 14th)
blogs_sans_isc·2026-07-14·CVSS 6.1
CVE-2026-56155 [MEDIUM] Microsoft Patch Tuesday July 2026 - The AI Acopolypse is Here , (Tue, Jul 14th)
Microsoft Patch Tuesday July 2026 - The AI Acopolypse is Here
Published: 2026-07-14. Last Updated: 2026-07-14 19:14:58 UTC
by Johannes Ullrich (Version: 1)
0 comment(s)
This patch Tuesday includes a staggering 622 vulnerabilities, not including another 427 vulnerabilities in Chromium, affecting Microsoft's Edge browser. 62 of the vulnerabilities are rated critical. One was disclosed before today, and two have already been exploited.
Given the large number of vulnerabilities, it is difficult to point out "noteworthy" issues.
Already exploited vulnerabilities:
CVE-2026-56155 : Active Directory Federation Services Elevation of Privilege Vulnerability. This is an important (not critical) vulnerablity.
CVE-2026-56164: Microsoft SharePoint Server Elevation of Privilege Vulnerability. Micr
Crowdstrike
July 2026 Patch Tuesday: Microsoft Patches 622 Vulnerabilities Including Two Exploited Zero-Days
blogs_crowdstrike
CVE-2026-56155 July 2026 Patch Tuesday: Microsoft Patches 622 Vulnerabilities Including Two Exploited Zero-Days
AIDR: How CrowdStrike Is Defining the Next Era of Cybersecurity Jul 15, 2026
July 2026 Patch Tuesday: Microsoft Patches 622 Vulnerabilities Including Two Exploited Zero-Days Jul 14, 2026
Why AI Governance Without Guardrails Is Theater Jul 09, 2026
Falcon Secure Access Sets the Standard for Zero Trust Browser Security Jul 08, 2026
AIDR: How CrowdStrike Is Defining the Next Era of Cybersecurity Jul 15, 2026
July 2026 Patch Tuesday: Microsoft Patches 622 Vulnerabilities Including Two Exploited Zero-Days Jul 14, 2026
Why AI Governance Without Guardrails Is Theater Jul 09, 2026
Falcon Secure Access Sets the Standard for Zero Trust Browser Security Jul 08, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&
2026-07-02
Published