CVE-2026-33111 | Microsoft Copilot Chat command injection (EUVD-2026-28449)
A vulnerability classified as critical was found in Microsoft Copilot Chat. Affected by this issue is some unknown functionality. The manipulation results in command injection.
This vulnerability is identified as CVE-2026-33111. The attack can be executed remotely. There is not any exploit available.
This product operates as a managed service, which prevents users from maintaining vulnerability countermeasures themselves.