CVE-2026-50517
An attacker can exploit multiple vulnerabilities in Microsoft Azure, Microsoft 365 Copilot, Microsoft Exchange, and Microsoft Apps Surface to escalate privileges, execute arbitrary code, manipulate data, or disclose confidential information.
CSIRTS triage
- What
- Multiple vulnerabilities can be exploited to escalate privileges, execute arbitrary code, manipulate data, or disclose confidential information.
- Who is affected
- Users of Microsoft Azure, Microsoft 365 Copilot, Microsoft Exchange, and Microsoft Apps Surface.
- Urgency
- Remediation is high urgency due to the severity and potential impact of the vulnerabilities.
- Action
- Update to the latest versions of the affected Microsoft products.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-50517
Get an email if CVE-2026-50517 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Moderate exploitation risk1.3% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 67% of all EPSS-scored CVEs.
Advisory coverage (3)
- high[NEW] [high] Microsoft Azure, Copilot, Exchange, Surface: Multiple vulnerabilitiescert-bund · 2026-07-27
- criticalCVE-2026-50517: Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute cod…nvd · 2026-07-24
- criticalCVE-2026-50517: Microsoft M365 Copilot Remote Code Execution Vulnerabilitymsrc · 2026-07-14
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-50517)