Microsoft has resolved a critical vulnerability in Microsoft 365 Copilot (CVE-2026-54130) that could have allowed attackers to execute code remotely. The fix was applied directly within Microsoft's cloud — businesses do not need to install any update or make any configuration changes.
- Vulnerability: CVE-2026-54130 in Microsoft 365 Copilot, rated critical with a CVSS score as high as 9.8.
- What it could allow: A successful exploit could give an attacker remote code execution capability within the affected environment — a significant risk if left unpatched.
- Who is affected: Any organisation using Microsoft 365 Copilot.
- How it was fixed: Microsoft classified this as an "Exclusively Hosted Service" vulnerability, meaning the fix was deployed within Microsoft's own cloud infrastructure. There is no security update, software build, or Admin Centre setting for your organisation to apply.
- What to do: No action is required. Microsoft has already resolved this on your behalf.
This is a useful reminder to keep your Microsoft 365 licences current — staying on active subscriptions ensures your organisation continues to receive security protections as Microsoft rolls them out automatically. Sources: MyABT.