CVE-2025-59286 | Microsoft 365 Copilots Business Chat command injection
A vulnerability labeled as critical has been found in Microsoft 365 Copilots Business Chat. Affected by this issue is some unknown functionality. The manipulation results in command injection.
This vulnerability is cataloged as CVE-2025-59286. The attack may be launched remotely. There is no exploit available.
This product operates as a managed service, which prevents users from maintaining vulnerability countermeasures themselves.