Trust & Security
Critical Copilot Vulnerability Chains With Exchange Online for Full M365 Tenant Compromise
CVE-2026-41106 (CVSS 9.3) in Microsoft 365 Copilot pairs with CVE-2026-54998 in Exchange Online to achieve unauthenticated remote privilege escalation — part of a broader cluster exposing the AI assistant as an attack surface.
◆ Heath Callahan