Microsoft patched a record 570 security flaws today, but one vulnerability stands out as a paradigm shift in AI risk.

CVE-2026-48561: A 9.6 CVSS critical remote code execution flaw in Microsoft Copilot allows attackers to execute arbitrary code over the network simply by hosting a malicious website. When a user visits that site, Microsoft Edge for Android automatically sends crafted prompts to Copilot, weaponizing the AI assistant itself.

This is not a theoretical risk. This is an active exploitation pathway where the productivity tool you trust becomes the backdoor into your system.

AI was supposed to secure our future. Instead, it has become the vulnerability.