CVE-2026-56167
An attacker can exploit multiple vulnerabilities in Microsoft Azure, Microsoft 365 Copilot, Microsoft Exchange, and Microsoft Apps Surface to escalate privileges, execute arbitrary code, manipulate data, or disclose confidential information.
CSIRTS triage
- What
- Multiple vulnerabilities can be exploited to escalate privileges, execute arbitrary code, manipulate data, or disclose confidential information.
- Who is affected
- Users of Microsoft Azure, Microsoft 365 Copilot, Microsoft Exchange, and Microsoft Apps Surface.
- Urgency
- Remediation is high urgency due to the severity and potential impact of the vulnerabilities.
- Action
- Update to the latest versions of the affected Microsoft products.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-56167
Get an email if CVE-2026-56167 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.41% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 33% of all EPSS-scored CVEs.
Advisory coverage (3)
- high[NEW] [high] Microsoft Azure, Copilot, Exchange, Surface: Multiple vulnerabilitiescert-bund · 2026-07-27
- highCVE-2026-56167: Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate…nvd · 2026-07-24
- highCVE-2026-56167: Azure AI Search Elevation of Privilege Vulnerabilitymsrc · 2026-07-14
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-56167)