CVE-2026-50517
Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.
CVSS
9.9
Critical
EPSS
—
KEV
—
Exploit Today
0
0-100
Published: Jul 24, 2026 · Last modified: Jul 24, 2026 · CWE-502
Not enough EPSS history yet.
Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-21655——
——0Deserialization of untrusted data vulnerability in Johnson Control victor on Windows allows capec-586.
This issue affects victor: from 2.9 before 3.0.2dCVE-2026-654977.2 HIG—
——0Administrator PHP Object Injection in Complianz <= 7.5.0 versions.2dCVE-2026-654937.5 HIG—
——0Subscriber PHP Object Injection in Dokan Pro <= 5.0.2 versions.2dCVE-2026-595449.8 CRI—
——0Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions.2dCVE-2026-167239.0 CRI47.9%
——14A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required.2dCVE-2026-612468.8 HIG38.6%
——12Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Platform Security for Java. Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).2d