[NEW] [high] Microsoft Windows Terminal and 365 Copilot: Multiple Vulnerabilities
An attacker can exploit multiple vulnerabilities in Microsoft Windows Terminal and Microsoft 365 Copilot to execute arbitrary code, present false information, and escalate their privileges.
CSIRTS triage
- What
- Multiple vulnerabilities allow an attacker to execute arbitrary code and escalate privileges.
- Who is affected
- Users of Microsoft Windows Terminal and Microsoft 365 Copilot are affected.
- Urgency
- Remediation is high priority due to the potential for exploitation.
- Action
- Update Microsoft Windows Terminal and 365 Copilot to the latest versions.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Windows Terminal and 365 Copilot
Get an email when a new Windows Terminal and 365 Copilot advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2320
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-541240.43% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 36% of all scored CVEs.
- Low exploitation riskCVE-2026-585950.46% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 37% of all scored CVEs.
- Low exploitation riskCVE-2026-504380.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 20% of all scored CVEs.
- Low exploitation riskCVE-2026-586360.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 19% of all scored CVEs.
- Low exploitation riskCVE-2026-411060.53% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 42% of all scored CVEs.
- Low exploitation riskCVE-2026-485610.76% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 52% of all scored CVEs.
- Low exploitation riskCVE-2026-586170.74% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 51% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-54124 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-58595 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-50438 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-58636 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-41106 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48561 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-58617 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownMultiple vulnerabilities in Microsoft Office (July 15, 2026)cert-fr-avis
- unknownMultiple vulnerabilities in Microsoft products (July 15, 2026)cert-fr-avis
- highCVE-2026-58617: Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to el…nvd
- highCVE-2026-54124: Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute …nvd
- highCVE-2026-50438: Improper link resolution before file access ('link following') in Microsoft PC Manager allows …nvd
- unknownexploitedNCSC-2026-0231 [1.00] [M/H] Vulnerabilities fixed in Microsoft Windowsncsc-nl
- highCVE-2026-58636: Improper link resolution before file access ('link following') in Window PC Manager allows an …nvd
- highCVE-2026-58595: Improper restriction of rendered ui layers or frames in Microsoft Bing App for IOS allows an u…nvd
- criticalCVE-2026-48561: Improper neutralization of special elements used in a command ('command injection') in Microso…nvd
- highCVE-2026-58636: Microsoft PC Manager Elevation of Privilege Vulnerabilitymsrc
- highCVE-2026-58595: Microsoft Bing App for IOS Spoofing Vulnerabilitymsrc
- highCVE-2026-54124: Windows Terminal Remote Code Execution Vulnerabilitymsrc
Recent advisories for Microsoft Windows Terminal
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- medium[NEW] [medium] Microsoft Windows Terminal: Vulnerability allows code executioncert-bund · 2026-07-17
More from CERT-Bund (BSI) Security Advisories
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow denial of service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow Denial of Service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow denial of service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow unspecified attack2026-07-31