CVE-2026-55946
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to
CVSS
6.1
Medium
EPSS
0.4%
p34
KEV
—
Exploit Today
10
0-100
Published: Sep 17, 2026 · Last modified: Sep 19, 2026 · CWE-77
0.4%EPSS · 30 days0.4%
2026-09-182026-09-19
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-937429.9 CRI78.5%
——24A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. Affected by this issue is the function formWsc of the file /boafrm/formWsc. This manipulation of the argument localPin causes command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.20hCVE-2026-935336.3 MED64.6%
——19A vulnerability was determined in spatie Scotty up to 1.4.4. This impacts the function DoctorCommand::checkSshConnectivity/DoctorCommand::checkRemoteTools of the file app/Commands/DoctorCommand.php of the component Doctor Command Handler. This manipulation of the argument host causes os command injection. It is possible to initiate the attack remotely. The pull request to fix this issue awaits acceptance.1dCVE-2026-886228.8 HIG63.8%
——19NUUO Network Video Recorder 2.0.0 is vulnerable to Command Injection in handle_import_privilege.php.2dCVE-2026-933718.3 HIG70.3%
——21A security vulnerability has been detected in marcopiovanello yt-dlp-web-ui up to v4. This issue affects the function NewGenericDownload of the file server/internal/downloaders/generic.go. Such manipulation of the argument params leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The name of the patch is c7ad3bd79c7c520a7d17e7f2ba19d962be8e7897. A patch should be applied to remediate this issue.2dCVE-2026-858859.9 CRI43.7%
——13Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized attacker to elevate privileges over a network.1dCVE-2026-785017.4 HIG41.0%
——12Improper neutralization of special elements used in a command ('command injection') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to disclose information over a network.2d