Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.8
CVE-2026-50523
Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an authorized attacker to execute …
Powershell
No fix yet
HIGH 7.8
CVE-2026-68792
Improper neutralization of special elements used in a command ('command injection') in Microsoft Office allows an authorized attacker to elevate priv…
365 Apps
No fix yet
HIGH 7.8
CVE-2026-65656
Improper neutralization of special elements used in a command ('command injection') in Microsoft Office allows an unauthorized attacker to execute co…
365 Apps
No fix yet
HIGH 8.8
CVE-2026-49179
Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to ex…
Windows 10 1607
10.0.14393.9418 / 10.0.17763.9115+
HIGH 7.2
CVE-2026-47299
Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent allows an authorized attacker to elevate p…
Azure Monitor Agent
1.43+
MEDIUM 6.5
CVE-2026-47285
Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to disclose…
Visual Studio Code
No fix yet
HIGH 8.8
CVE-2026-56197
Improper neutralization of special elements used in a command ('command injection') in Windows Admin Center allows an authorized attacker to execute …
Windows Admin Center
2606+
HIGH 7.1
CVE-2026-55145
Improper neutralization of special elements used in a command ('command injection') in Outlook Copilot allows an authorized attacker to perform tampe…
Copilot
Mitigation only
HIGH 7.8
CVE-2026-50488
Improper neutralization of special elements used in a command ('command injection') in Windows Clipboard User Service allows an authorized attacker t…
Windows 11 24h2
10.0.26100.8875 / 10.0.26100.33158+
HIGH 7.8
CVE-2026-58635
Improper neutralization of special elements used in a command ('command injection') in Windows Narrator Braille allows an authorized attacker to elev…
Windows 10 1809
10.0.17763.9020 / 10.0.19044.7548+
HIGH 8.4
CVE-2026-50520
Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to execute …
Visual Studio Code
1.128.1+
CRITICAL 9.6
CVE-2026-48561
Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker …
365 Copilot
Mitigation only
HIGH 7.5
CVE-2026-42895
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform t…
365 Copilot
Mitigation only
HIGH 8.8
CVE-2026-45497
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an authorized attacker to execute cod…
Copilot
Mitigation only
HIGH 7.5
CVE-2026-42824EPSS 8%
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose infor…
Copilot
Mitigation only
HIGH 7.5
CVE-2026-42827
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose infor…
365 Copilot
Mitigation only
CRITICAL 9.3
CVE-2026-41090
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform t…
365 Copilot
Mitigation only
CRITICAL 9.8
CVE-2026-23652
Improper neutralization of special elements used in a command ('command injection') in Microsoft Power Pages allows an unauthorized attacker to execu…
Power Pages
Mitigation only
MEDIUM 6.8
CVE-2026-45585
Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". The proof of concept for this…
Windows 11 24h2
No fix yet
HIGH 7.5
CVE-2026-42893
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to perform tamper…
Outlook
5.2617.1+
CRITICAL 9.6
CVE-2026-35428
Improper neutralization of special elements used in a command ('command injection') in Azure Cloud Shell allows an unauthorized attacker to perform s…
Azure Cloud Shell
Mitigation only
HIGH 7.5
CVE-2026-33111
Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker …
Copilot Chat
Mitigation only
HIGH 7.8
CVE-2026-32183
Improper neutralization of special elements used in a command ('command injection') in Windows Snipping Tool allows an unauthorized attacker to execu…
Windows 10 1607
10.0.14393.9060 / 10.0.17763.8644+
MEDIUM 6.5
CVE-2026-23653
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an authorized att…
Github Copilot Chat
0.37.3+
CRITICAL 9.8
CVE-2026-32194
Improper neutralization of special elements used in a command ('command injection') in Microsoft Bing Images allows an unauthorized attacker to execu…
Bing Images
No fix yet
HIGH 7.5
CVE-2026-26136
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose …
Copilot
Mitigation only
MEDIUM 5.3
CVE-2026-24299
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose infor…
365 Copilot
Mitigation only
HIGH 7.1
CVE-2026-26133
AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.
365 Copilot
2.2.260210.21290750 / 2.106+
HIGH 8.8
CVE-2026-21518
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized a…
Visual Studio Code
1.109.2+
MEDIUM 6.7
CVE-2026-21522
Improper neutralization of special elements used in a command ('command injection') in Azure Compute Gallery allows an authorized attacker to elevate…
Confcom
1.2.8+