AI analysis
CVE-2026-85885 is a command injection flaw (CWE-77) in Microsoft 365 Copilot in which special elements in user-supplied input are improperly neutralized before being passed to a command interpreter. An authorized, low-privileged user can trigger it over the network with crafted input and no user interaction or special conditions. Successful exploitation elevates the attacker's privileges, with high impact to confidentiality, integrity, and availability, and the changed scope in the CVSS vector indicates impact can extend beyond the initially compromised component. Any organization whose users have Microsoft 365 Copilot enabled is in scope, since the flaw resides in Microsoft's cloud service rather than a locally installed product. There is currently no evidence of exploitation in the wild, no public proof-of-concept, and the flaw is not listed in CISA's KEV catalog.
What to do: Check the MSRC advisory for CVE-2026-85885 and confirm your tenant has received Microsoft's server-side update, since fixes for the Copilot cloud service are deployed by Microsoft rather than patched locally. In the interim, limit Copilot licenses and access to users who need them and review Microsoft 365 audit logs for unusual privileged actions originating from low-privileged accounts. If the advisory lists any client-side component version to update, apply it promptly.
Estimated exposure
mass≈100M users / tens of millions of paid enterprise seats (Microsoft-reported M365 Copilot monthly active user base) — Microsoft 365 Copilot is a cloud service with very broad enterprise adoption (Microsoft has publicly reported a monthly active user base on the order of 100 million, including the majority of the Fortune 500), and every tenant with Copilot…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.