CyberICT

CVE-2026-21521

Microsoft · Published January 22, 2026

CVSS v3.1

HIGH
Patch availableGet patch

Description

Word Copilot Information Disclosure Vulnerability. Improper neutralization of escape, meta, or control sequences in Copilot allows an unauthorized attacker to disclose information over a network.

Affected Products

  • Microsoft 365 Word Copilot

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C