CVE-2026-21521
Microsoft · Published January 22, 2026
7.4
CVSS v3.1
HIGHPatch availableGet patch
Description
Word Copilot Information Disclosure Vulnerability. Improper neutralization of escape, meta, or control sequences in Copilot allows an unauthorized attacker to disclose information over a network.
Affected Products
- Microsoft 365 Word Copilot
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C