Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2026-78501
Microsoft 365 Copilot Business Chat Information Disclosure Vulnerability
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N C H N N 8.6 .0089 58.2 —
AFFECTED
Product Versions Fixed
Microsoft 365 Copilot's Business Chat - – —
TIMELINE
Aug 24 Reserved by microsoft
Sep 17 Published (CNA: microsoft)
Oct 7 RESCORED — CVE-2026-78501 (Microsoft 365 Copilot's Business Chat). CVSS 7.4 → 8.6 (NVD).
Description
Improper neutralization of special elements used in a command ('command injection') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to disclose information over a network.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| August 24, 2026 | Reserved | Reserved by microsoft |
| September 17, 2026 | Published | Published (CNA: microsoft) |
| October 7, 2026 | RESCORED | RESCORED — CVE-2026-78501 (Microsoft 365 Copilot's Business Chat). CVSS 7.4 → 8.6 (NVD). |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Microsoft | Microsoft 365 Copilot's Business Chat | — | - | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-78501 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Thursday, October 8, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.